• 1 Post
  • 41 Comments
Joined 3 years ago
cake
Cake day: July 2nd, 2023

help-circle

  • Tetsuo@jlai.lutoSelfhosted@lemmy.world[AIT] The Codeberg ban on LLM content
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    3
    ·
    20 days ago

    https://malus.sh/

    AIs already pillaged all the code in the world. This is fighting a lost fight. We won’t manage to force big AI firms that literally props a country to stay afloat to make their AI “forget” or “untrained”.

    Regulators let the pillaging happen so now AI does know how to code. They dont imitate they truly code.

    But IMO the real fight is about things like malus that are the real dangerous and malevolent actor here. They will take your open source code and resell it to big businesses.


  • I’m the only linux user in my group of friends and fortunately my switch didn’t change anything.

    I never was late or anything to play because every game starts well now. My controller only works when steam is started though so I think I still can improve that by installing the steam compatibility driver package thing.

    Honestly dont give up OP. Once you will have completely setup your games and got to know your system better it will run fine.

    I also hated Windows so much I moved to cachyos earlier this year and I’m not turning back. Also I have never played as much video games since my switch to cachyos. The change of OS and the fact that I again feel “in control” of my computer again had somehow reinvigorated my fun playing games with friends.

    Basically, OP, dont give up! If I can make it everyday with my group of friends, you can manage it too with yours (even if they sound rather immature). Honestly once you will have setup games on proton so many times you will be able to avoid most problems in a matter of minutes.

    IE we bought and played a game on a whim with 4 players. It wasn’t working on cachyos-proton so I quickly changed it to my emergency GE-Proton compatibility and it worked right away.





  • That was my understanding but I’m not sure I agree with your conclusion though.

    This hack drops an infostealer that could steal passwords and other secrets, so even if the system removes the malware, the data stolen would still be an issue.

    So you can be infected for even a few days and get some passwords stolen that would still be problematic.

    But yeah the subset of Steamdeck users that activated write mode and installed an affected AUR package must be pretty small.



  • Either Linux’s built-in display drivers are black magic or microslop is incompetent

    Why not both :) ?

    I just realized that since switching to cachyos 4 months ago I have never had to install any driver or driver updates (outside of just running the system update).

    Even during initial setup I don’t think I installed anything driver related.

    It’s really a step up from Microslop. Last time I installed my W10 I had to prepare all the necessary drivers and collect them on each manufacturers websites.

    It is so much more streamlined on Linux.




  • They could also put a checking tool into CachyOS Hello, which is shipped and pops up by default.

    What would this “checking tool” look like? What would it check?

    I personally have deactivated the opening cachyos Hello a long time ago. Why would I need that popup once I setup everything?

    And I’ve definitely gotten “urgent” text notifications that all-but-required manual action through pacman.

    Pacman has no idea if it is installing something malicious. It notifies you only on functional actions that are required.

    Basically, none of the suggestions you make would have avoided the AUR attack to work. Nor a future one?

    The only thing I would maybe agree is for some notification system that let’s the cachyos maintainers send an urgent message but that would mean they would have to sign that message in some way. If that signature verification ever fails someone could send malicious notifications to all cachyos users and that would create another threat.

    And even then if the malicious package is noticed after a few days, if you already installed/updated it, it’s too late. You could receive a notification giving guidelines to cleanup but that’s too late. The infection could disable these notifications or worse.

    And if you have an emergency notifications systems, is it a “pull” or “push” notification? Is it your computer that checks if there is a notification? How long between pulls? If that’s a push then the notification servers basically has a full list of cachyos IPs which would suck too.

    Sorry if I look nitpicky but I just want to illustrate that this is a very very complex problem to solve while respecting user privacy and “sovereignty” over their system. Supply chain attacks are extremely difficult to defend against and open source projects have increasingly numerous dependencies…


  • How else would you have wanted to be warned ?

    In my opinion that’s the other side of the privacy coin.

    What happens on my system is only for me to check. And in that case that means I’m on my own to be aware of its current state.

    I mean the cachyos devs or the AUR maintainer have in some way by design no way to reach me. And creating some kind of malware monitoring or scanning tool included by default would be against the ethos of the OS…

    So it’s up to each user to determine if they want to use random scripts or just read the blog of their OS and do everything manually. There isn’t an adequate universal solution there.



  • I think you understand correctly.

    Your setup seems quite insecure considering your keyring seems to be always open and that you use a password that is already used to login.

    On the other hand a keyring can be unlocked only when used and could also have it’s own dedicated password for it. Security is more a gradient than something binary.

    Also if you store keys that are particularly sensitive in it they are as vulnerable as the container that stores them.

    Not blaming you of anything of course, I think you are asking the right questions. 👍


  • Tetsuo@jlai.lutoLinux@lemmy.ml*Permanently Deleted*
    link
    fedilink
    arrow-up
    6
    arrow-down
    1
    ·
    2 months ago

    I suspect the AI use is the problem.

    AI are very keen on recommending deep modification of your system. And then they quickly forget they asked you to recompile your own kernel based on a 2014 forum post. I’m fairly knowledgeable on Linux and if I would have naïvely listened to Deepseek I would have destroyed my system many times. And that’s even with prompts asking the AI to avoid outdated sources and to ask me for current configs.

    I believe you would boot a liveUSB of cachyos, install that terrible idea of a browser and it would work straight away. Well if you ask AI on how to install it then it will probably recommend you to compile it yourself etc… Or to use some weird AUR repo… So maybe that’s the right context to actually use the Arch Wiki on an arch based distro ? But please, enough improvisation with AI, you breaking your system in a subtle but critical way is just one AI hallucination away.

    So basically my advice is to try on cachyos without ever using AI. Just the wiki for cachyos, then the Arch wiki and finally the cachyos forum asking politely and in a detailed manner for help and being patient.

    The very premise of all of this is still crazy though. There is no feature in Brave that would justify tossing a whole operating system for…


  • I worked for years on a large email infrastructure for a job and for me it’s absolutely not worth it either.

    I would prefer to take a subscription on a reputable host.

    Why?

    Because even if I do everything perfectly at setup (TLS, SPF, DKIM, DMARC) that will still be precarious.

    The security of SMTP is a patchwork of protocols added on top of it and a bunch of opaque reputation systems. If anything ever goes wrong with my email my domain’s reputation would fall. And that’s the thing, once your domain reputation goes too low, you can’t fix right away and say “my bad” and recover. Your mail will be silently blocked like Spam until a few days of sending perfectly clean emails. You need time to recover.

    So mail self hosting is accepting that at any time if you make a slight mistake, your communications to other will be almost impossible for days. And again since a lot of it is reputation based you can’t fix the issue and recover immediately.

    The business I was working for had everyday scenarios like that. A client that failed to update its DKIM and didn’t notice right away. When they do their reputation on for example Cisco’s platform is super low and we filter them as spam. And then it took days for them to recover even if they fixed the DKIM just one or two days after their mistake.

    On the other hand I could take a protonmail subscription and use a domain that has so much volume and is tracked so carefully in term of reputation that I know my mails will be received and have all the necessary security done right.

    These reputation systems are inherently difficult for small volume mail domains. There is no other users ln your domain so one mistake is all it takes to start having delivery issues and most importantly silent failed deliveries that you dont know about.

    Is it possible? Yes. Is it necessary? Not really. If you can pay for a privacy respecting host…

    Hence for me it’s not worth it because there are privacy respecting providers so it’s not like I absolutely have to self host it.


  • I tried doing manually a gamescope command line arguments for Overwatch and it didn’t work.

    I activated the necessary flags and took close attention to the resolution in game and of my display, made sur the game had HDR enabled etc and it never worked.

    So if I can’t get HDR to work even with gamescope on a stable game like OW…

    But your tip to setup gamescope for the session is interesting. I might try that out sometimes.

    But honestly HDR is quite anecdotal for me. It’s not that visible. I much prefer to focus on optimizing FPS and input delay than tweaking for HDR.


  • I never tried Garuda so I can’t help with the comparison.

    Is Garuda debian based ?

    Cachyos is the first time I touched an Arch based distro and I was very impressed by how stable and “fresh” it feels. I guess Arch deserves its good reputation.

    I have been updating my cachyos like two times each week which is a quite high update rate and the only problem I had was this :

    Steam stored his cache by default on my home partition and filled the disk completely. I then updated with pacman without noticing I had no space left and the process failed. The system wouldn’t boot which was scary. I took a bit of time to think about it and remembered that I can revert the system with BTRFS snapshot. So I checked the cachyos wiki on how to revert and in 2mn i was back to the exact state before my failed update. It broke once because of Steam and the system was very easy to fix.

    A beginners could learn to use snapshots easily in the GUI for it and I think would succeed in restoring the system. Would the same be true if a Windows didn’t boot ? Honestly I don’t think so.

    I even was able to setup in the GUI for how many snapshots I want to keep so i constantly have around 30 snaps ready to recover my system up to a month and a half ago.


  • Tetsuo@jlai.lutoLinux@lemmy.ml*Permanently Deleted*
    link
    fedilink
    arrow-up
    45
    ·
    2 months ago

    Pros :

    • Reliable, I have nothing to fix and no unusual behaviors or settings on Cachyos. If I set something up the setting won’t change on its own.
    • Private, no telemetry. No NVIDIA service sending all the apps I launch to HQ.
    • No forced software. I can choose to remove most components I dont like and replace them.
    • Gaming works as well or better than Windows once its setup.
    • I can revert to a previous image of my system right at boot. Very reassuring to know it’s easy to revert to a previous state/version of my system.
    • More lightweight system, I use way less RAM on idle than on Windows. That’s more RAM to use for actual useful stuff like gaming.
    • it’s free. Doesn’t require an account to use.
    • it’s secure. Much less risk running a linux system than windows. You are a harder target and also a less attractive one for hackers.

    Cons :

    • I can’t play games with kernel level anticheats.
    • I sometimes have to spend 10mn when installing a new game to set it up on proton.
    • You are still expected by most people to handle their proprietary files coming from Microslop. You have to be able to sign PDF files and return office files.
    • HDR support is not really good for games and it often is difficult to have working.

    Overall, having switched 4 months ago, I have no regrets and honestly it was a great upgrade for me. Beside the money lost on a game like BF6 I’m very happy to be on linux.

    I was really annoyed by my W10 setup anyway. I constantly had settings that would change on their own. I often had bad days where you feel the system struggling even though nothing changed. It was very frustrating. Linux solved that. I dont have bad days on my system. It runs exactly as I left it when it was shutdown. And this expected stability is very comfortable for users.

    Highly recommend the switch to cachyos for all Windows gamers. And even for non-gamers it’s a very functional and reliable operating system.