LnL has quit [Ping timeout: 244 seconds]
pie__ has joined #nixos-security
pie___ has quit [Ping timeout: 250 seconds]
MichaelRaskin has quit [Quit: MichaelRaskin]
LnL has joined #nixos-security
periklis has joined #nixos-security
periklis has quit [Ping timeout: 246 seconds]
sphalerite has quit [Ping timeout: 268 seconds]
sphalerite has joined #nixos-security
* Foxboron prepares for the screaming choir
<gchristensen> this is great!
<gchristensen> I really appreciate the fine toothed comb systemd is getting
<andi-> Foxboron: do you have the lyrics ready?
* Foxboron attempts finding a song that asks everyone to be nice
<pie__> im usually the one doing the screaming so i will oblige
<pie__> hey i have a new hot-take this time though
<pie__> the part where they messed up systemd is deciding to write it in c
<Foxboron> Lennart is inclined to agree, as it so turns out.
<pie__> they started it before rust really took off though i guess
<pie__> quick hard-bank before the sunk cost fallacy kicks i-ohwait? :P
<pie__> (except it not really completely a fallacy i guess)
<Foxboron> choir on reddit is screaming. I should stay off reddit
<gchristensen> it isn't useful
<gchristensen> it just makes everybody feel crappy and down while adding little to no value
<gchristensen> (in my experience) systemd fixes so much stuff which was really horrible to deal with, and I'm glad for it constantly
<gchristensen> there are bugs everywhere, but as soon as one in systemd specifically crops up it is "oh man, look at that, systemd fucked up again"
<gchristensen> meanwhile there have been dozens to hundreds of CVEs which were issued against not-systemd.
<Foxboron> indeed
<Foxboron> Pointed out that there are 10-15 Linux DoS CVEs filed for every 1 systemd DoS CVE
<Foxboron> which are exactly 2. So it's probably closer to 20-30 Linux DoS CVEs :p
<gchristensen> it is wildly cool that you can use native features in your service manager to drop basically all the capabilities if you want
<gchristensen> yeah
<gchristensen> all our software is buggy as hell, it just is a fact of writing software -- systemd is no exception
<Foxboron> One in KVM it seems!
<gchristensen> you know what would be cool? working to improve it
<gchristensen> the people reviewing and finding these bugs in systemd are doing exactly that, which I'm grateful for
<gchristensen> the howling is not
* andi- agrees
<Foxboron> Well, it's hard when the loudest voice on reddit (currently) is patching systemd :p
<gchristensen> also, the sky isn't falling every time there is a CVE
<Foxboron> then also yells at how bloated it is
<Foxboron> gchristensen: Haha. I wrote the same thing!
<Foxboron> heh
<gchristensen> haha
<disasm> we should hammer the reddit thread with if you used nixos, you could patch your system with one command without worrying of breakage :)
<gchristensen> it has been a while since the last "y'all suck for using systemd" troll in #nixos, not sure I want to tempt fait :P
<gchristensen> fate*
<disasm> true
<disasm> my biggest problem with the first one was figuring out how to get a bunch of code that hadn't been updated in a year working on 18.09
<disasm> and I could have just cherry-picked the patch to 18.03, but I kinda wanted an excuse to update to 18.09.
<pie__> i complain about those too :P <gchristensen> meanwhile there have been dozens to hundreds of CVEs which were issued against not-systemd.
<gchristensen> those aren't helping either lol
<gchristensen> it just feels crappy
<pie__> i know xP
<pie__> :(
<gchristensen> and I've not been actively patching for a while, but security patching is really risk for burnout, and panic over them makes it worse
<pie__> honesly most of the time its "for fucks sake guys we need to find automated ays to not run into this shit, how long have we been doing this now?"
<pie__> ^for m
<pie__> ^for me
<pie__> (ok i was mostly joking about the sky falling for me evey time, im still young)
<ekleog> Foxboron: IMO, people yell at systemd because they know the world before systemd. Linux is too much anchored in the “well you've got no choice, just use it” mindset that people no longer even care about it
<ekleog> just give a few decades to systemd and it'll come there
<Foxboron> I'm from a different camp so I'm not going to continue that debate :)
* Foxboron wants everyone to get along
<pie__> \o/
* pie__ passes out hugs
pie__ has quit [Ping timeout: 250 seconds]
<samueldr> *++ for the positivity in CVE