"More easily configurable" would be more accurate, because there's less things that could get in your way. The system is designed to make it as simple as possible from a developers perspective.
That wouldn't have fixed the AUR incident because the attacker updated the PKGBUILD which is roughly the same as the nixfile. And there are no packages provided by the AUR, just PKGBUILDs. You always build the package yourself locally.
Official packages are already vetted so they don't need user scoping. They could just enforce user scoping in the AUR and use the provides array for resolving conflicts. Its not a perfect solution but there's no such thing as perfect security, just better security.
Also having an AUR helper that properly containerized the build step would be an even bigger improvement.
Arch is deliberately minimal making it a good base system in the same way Debian or Fedora is. It's smaller, simpler, updates faster than the others and is far more configurable. It is however not built for the average user and most distros built on top of it that try to make it more "usable" are IMO pretty dangerous ideas. I think the only derivative i've tried that was good was SteamOS because they made it Atomic like nix or silverblue.
None of this really has to do with the AUR. That was always labelled as "use at your own risk". And to their credit they caught and addressed the attack within a day of it happening. Still, hosting user PKGBUILDs and leaving it to individual users to audit them is not a secure solution, its just punting on the responsibility.
npm: Node Package Manager.
AUR: Arch User Repository.
Bazzite is based on fedora not Arch so you don't need to worry.
The batteries inside the pack are far cheaper. Opening the pack to replace them will be a challenge.
The GCC all the Arab nations on the other side of the Persian gulf that got their shit rocked for hosting US bases. They are not in a position to make any demands.
The US is letting Iran access its own money that the US had frozen with sanctions. Same as with the JCPOA. The US tax payers are not footing this bill.
Update only $25B is from frozen assets, the $300B is from the GCC. The people we dragged into this war are footing the bill. LOL fuck the UAE.
Sounds like the same stockholm syndrome I have for Arch.
some problems are better solved via OOP, others through functional programming. The perfect language would be a successful blend of the two.
That was the entire goal of Scala and I would say Scala both accomplished it and is a worse language for doing so. Some OOP principles are just bad, namely subtyping. Rust genuinely does blend OOP and Functional in a better way. Instead of classes and interfaces with lambdas you have algebraic data types and type classes with for loops.
Some of my services (eg headscale) are public and a firewall would block those since it doesn't know what a domain name is, just IPs and ports.
I do have a firewall fwiw but it keeps 443 open. Otherwise a remote device wouldn't be able to connect to the headscale node and get onto my tailnet.
Dudes turning into the proverbial corn cob on the social media site he owns.