cross-posted from: https://sh.itjust.works/post/62361303

Hello good people.

Is no one afraid of Bazzites auto updating nature?

I am myself worried about the potential for well timed supply chain attacks from wherever they build their OS images, which somehow build malicious images or just gets itself into the normal image builds and we auto update to.

Is this an unfounded worry? Does anyone know of the security measures in place to prevent attacks?

Auto update just feels weird to me, especially for something like my OS. I’m asking because I went and installed it and realised auto updating seems to be their philosophy… which is scary?

p.s. i couldnt find anyone online discussing this

Thonks

  • 6_Electrons@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    3 hours ago

    This was one of the reasons I went to kinoite. Part of leaving Windows was to get away from all their slop… The other part was to get away all the forced updates. I don’t wanna be forced to update if I don’t want too

    Edit: to illustrate your point look at the stories of people who can’t use virilization anymore because they took out virt-manager and QEMU but did a horrible job of telling people and then stuff updated.

    Now they rebase to -dx, layer the packages or go someplace else.

    • dogs0n@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      2
      ·
      3 hours ago

      Thanks for the answer.

      That’s good to be aware of. I was also kinda put a back by a github issue raised by someone who could no longer toggle off auto updates with ujust.

      It got solved by them adding the command back, just to be silently broken again by them renaming and subsequently removing it again (still removed as far as I’m aware).

      Weird first impression on how quickly things are broken with no alternative.