17 Aug 2021 |
@vherrmann:shmerver.de | It's just that it's easier to mess with binaries | 15:29:24 |
@timdeh:matrix.org | Because of the way nix hashes packages, you would only have to trust me if source wasn't available. | 15:29:29 |
@vherrmann:shmerver.de | but, whatever | 15:29:29 |
@vherrmann:shmerver.de | hm | 15:29:39 |
@vherrmann:shmerver.de | yes, with nix it's pretty easy to validate the packages | 15:30:00 |
@timdeh:matrix.org | if I changed anything, it would change the hash, and it would be a cache miss | 15:30:08 |
@vherrmann:shmerver.de | But for that i would have to build them, or not? | 15:30:12 |
@vherrmann:shmerver.de | or no, as long as i trust cachix, i don't have to trust you, am i right? | 15:30:43 |
@timdeh:matrix.org | no | 15:30:47 |
@vherrmann:shmerver.de | so, you're saying i have to trust you? | 15:31:25 |
@vherrmann:shmerver.de | hm | 15:33:15 |
@vherrmann:shmerver.de | well anyways… | 15:33:33 |
@vherrmann:shmerver.de | there are millions of other security issues with my setup | 15:34:06 |
@vherrmann:shmerver.de | (Just like most setups have millions of security issues) | 15:37:57 |
@timdeh:matrix.org | no I'm not | 15:38:10 |
@timdeh:matrix.org | I'm saying if I changed anything, it would be a cache miss | 15:38:23 |
@timdeh:matrix.org | (for you) | 15:38:33 |
@timdeh:matrix.org | so if I take package A from DevOS and secretly modify a line, and upload the result in cachix, and then you come and download package A from DevOS, you will not download my modified version, because my version has a different hash, which without the source, you can't even calculate. | 15:39:32 |
18 Aug 2021 |
David Arnold (blaggacao) | In reply to @vherrmann:shmerver.de So its opt-out and not opt-in The config settings you refer to are opt-in. You will be explicitly asked by the cli if you trust them, and if you want to record that decision for future invokations. | 00:02:55 |
ultranix | that would be.. opt in | 04:41:28 |
@vherrmann:shmerver.de | lol, i forgot that | 05:17:58 |
@vherrmann:shmerver.de | :S | 05:27:45 |
@timdeh:matrix.org | no worries 😅 | 17:28:54 |
19 Aug 2021 |
| @gromzly:fullthese.website joined the room. | 14:40:59 |
David Arnold (blaggacao) | I made the nix-patch overlay use the latest version of nix & that also should save us for a while w.r.t. the follows patch.... | 23:29:24 |
David Arnold (blaggacao) | https://github.com/divnix/digga/commit/2c5953f284690a89bfd472418141e3afea2dcf5d | 23:29:25 |
20 Aug 2021 |
David Arnold (blaggacao) | So do we abolish the all profile tests then? | 01:17:20 |
David Arnold (blaggacao) | [Poll] Agree
0. yes
1. maybe | 01:17:45 |
David Arnold (blaggacao) | 😁 | 01:17:48 |
David Arnold (blaggacao) | 0. yes | 01:18:00 |