[Discuss] sudo
bctill
bctill at ece.uvic.ca
Tue Apr 4 13:08:10 PDT 2023
On 2023-04-04 11:50, BCLUG wrote:
> bctill wrote on 2023-04-04 11:35:
>
>> I'm not at all sure, but it seems to me that this is the more generic
>> and versatile approach. I don't know enough yet to compare the pros
>> and cons of LFS vs. Gentoo, but I would love to hear your thoughts
>> about that.
>
> As far as I know, Gentoo comes with package management (evince?),
> whereas LFS means you get to find out when software has new releases,
> where those releases are stored, pull them down, compile them, install
> them - all manually.
>
>
> LFS seems like a great learning tool, but utterly unfit for a
> production machine (IMHO).
>
>
>> Debian, on the other hand, seems to be the at or near the center of
>> the FOSS universe, and the more developers you have scrutinizing your
>> source code, the more secure and reliable it's likely to be.
>
> This is an important consideration and I'm quoting it to agree with it.
>
>
>> The main objections that people have about Debian is its heavy
>> dependency on systemd
>
> Again, it (systemd) is at the centre of the FOSS universe now and has
> many dev's eyes on it.
>
>
>> and its slowness to adopt new versions of packages.
>
> This is one reason I've never dabbled with Debian.
>
>
>> If I only have to recompile my installation once every few years,
>> that is a definite plus!
>
> If security is a concern (it should be), you'd want to be more
> up-to-date than "every few years".
>
>
>
> There are a lot of trade-offs in choosing a distro, just adding my
> thoughts...
>
>
>
> rb
>
> (Happy user of KDEneon desktop, and Ubuntu server on servers.)
>
>
> _______________________________________________
> Discuss mailing list
> Discuss at vlug.org
> http://vlug.org/mailman/listinfo/discuss_vlug.org
Hi rb --
"LFS seems like a great learning tool, but utterly unfit for a
production machine"
I completely agree.
"(systemd) is at the centre of the FOSS universe now and has many dev's
eyes on it"
True, but what worries me is the culture of the core development team.
They're all paid by Red Hat, and that alone should make the rest of us
suspicious.
Windows has developed a culture that takes it for granted that Microsoft
can be trusted but the computer owner can not. And, further, that
forced updates and always-on telemetry are not invasions of privacy.
Companies like Red Hat and Canonical seem hell-bent on bringing that
culture to Linux.
"If security is a concern (it should be), you'd want to be more
up-to-date than "every few years"."
Yes of course, but surely I don't have to recompile the whole system
every time a security patch comes along?
When updates and patches come along, would I not be in a position to
decide for myself which ones to reject, which ones to apply, and which
ones warrant a recompile?
Also, the ability to compile from source gives me a way to defend
against developers who bundle unwanted updates with necessary security
patches.
Regards,
-- Bernie.
More information about the Discuss
mailing list