• rumba@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 day ago

    I would argue it’s harder to get a root exploit on Silverblue because more of the filesystem is less mutable and applications are more sandboxed.

    I’m running NixOS because declarative is saving me time on system changes nad keeping multiple workstations synced up.

    SB is more well protected against unauthorized system changes, Nix is more flexible while still providing good rollbacks.

    • iopq@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      17 hours ago

      Nobody is forcing you to install system applications on NixOS. I use flatpaks on it all the time

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 hours ago

        I hate flatpacks worse than I hate snap

        I spent their better part of two days wourth of spare time trying to get OBS and flat packs to take plugins.

        To be honest, I only install stuff that I use everyday and randomly. For anything that’s part of a certain project or subsystem either use nix develop or nix shell.

        I have one that activates kdenlive, makes YTDLP available, FFmpeg, MPV, and then when I exit that shell all that stuff is no longer linked.

        Likewise I have oodles of rust and python projects that only bring into being what they need to get the work done.

        • iopq@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          5 hours ago

          Nah, I hate snap much more. Can’t even install the normal version is Firefox anymore on Ubuntu without hunting online for an installer