{`-`} has joined #nixos-security
<pie__> would it be appropriate to default this to off on a nixos level? https://blog.powerdns.com/2018/09/04/on-firefox-moving-dns-to-a-third-party/
<pie__> i guess probably not?
<pie__> (assuming it goes through)
<gchristensen> probably not, we have to keep it to be standard with upstream to call it Firefox
<andi-> We could add an unbranded "secure" Firefox in addition.. But not sure that would be maintained.
<andi-> pie__: have you tought about using a group policies like thing for those settings? I've never done that but supposedly such mechanisms exist.. if we would allow users (without the defaults?) to configure it system wide that should be fine?
<pie__> andi-, idk about group policies but i know windows has stuff like that
<pie__> i would like it if nix(os/pkgs) had more functionality for configuring end user apps
<pie__> probably falls in the scope of nix-home or whatsit
<pie__> gchristensen, hm.
<andi-> I think system wide defaults could be part of nixos
<andi-> But even then I'd probably not be happy with disabling it by default.. it feels like a cheap hack around their policies?
<pie__> idk *shrug* :/
<pie__> well, maybe nixpkgs needs a "paranoid" "branch"
<pie__> :P
<pie__> drop some qubesOS stuff in there, etc etc
<pie__> that would be nice
<pie__> </offtopic>
{^_^} has quit [Remote host closed the connection]
{^_^} has joined #nixos-security