Failing to renew TLS certificates on time multiple times is enough to never touch it again, but there’s also been a lot of other problems with Manjaro.
When I used Manjaro, it never made it more than 6 weeks before something would catastrophically break and I’d have to roll back using snapshots.
The manifesto mentions this and that tooling had been made by volunteers but leadership ignored or rejected it (wasn’t clear which). So it seems that they are firing their leadership for the same reasons you want to stay away, which is a good sign, at least. Like promising that they are willing to mutiny to stop the enshitification.
Keep the dumbass reddit style “jokes” to reddit. Either answer the question or stfu. You’re not funny and your lame attempt at a “joke” is just annoying.
Could you please explain why not renewing their certs is such a serious betrayal? Like, if they fixed it, isn’t that okay? And even if it happened again, and they fixed it again, isn’t it human to err? Or why is it such a harsh offense?
Serious question, I don’t know the consequences of not renewing these certs. 😊
It’s the tls certificate that proves your website is legit. Without which, you can potentially be a malicious actor that can pose as the website, and when you download the iso, you could unknowingly download something malicious. It’s pretty hard to forget certificate renewal (most of the time there are plenty of reminders sent and warnings given), so the fact that it happened twice was very impressively bad.
It’s pretty hard to forget certificate renewal (most of the time there are plenty of reminders sent and warnings given)
Oh boy. Seems to be the opposite in real life. Especially when it comes to managing stored cert of businesses partners. It has gotten somewhat better now of course, but three years ago most of my company’s sev1 production issues were due to lapsing or unscheduled cert changes.
People are very harsh with Manjaro. There’s more than just a list of objective facts unfortunately. I suppose there were some bruised egos at some point.
The certs issue wasn’t a big deal, it didn’t change anything for me as a user. It just paints a bad image.
As a former Manjaro user, it has some issues. It has weird bugs that aren’t present in any other Arch-based distro. Pamac ddosing the AUR is pretty bad as well. I’m thankful I used it as long as I did though. It got me hooked on Arch based distros. Everything else feels antiquated now. Actually, Void Linux is kinda cool
it’s the main way for software to verify the identity of a source. without it you let nefarious actors do something like hijack a DNS server and impersonate your servers to your users, which is a pretty big problem if you’re running a software distribution network! it is literally a breach of trust and massive security vulnerability. and it probably broke a ton of shit when software that uses the certificate found an expired one and suddenly (and correctly) refused to work.
What happened?
Failing to renew TLS certificates on time multiple times is enough to never touch it again, but there’s also been a lot of other problems with Manjaro.
When I used Manjaro, it never made it more than 6 weeks before something would catastrophically break and I’d have to roll back using snapshots.
The manifesto mentions this and that tooling had been made by volunteers but leadership ignored or rejected it (wasn’t clear which). So it seems that they are firing their leadership for the same reasons you want to stay away, which is a good sign, at least. Like promising that they are willing to mutiny to stop the enshitification.
Yeah the last time I tried manjaro years ago it kept breaking but I thought that was just the linux experience at the time haha
+1
The trust. It eroded.
I mean, I think they were looking for a little more detail that that.
Over a hundred thousand years the ocean of distrust has eroded the cliffs of trust in a non-insignificant manner.
Keep the dumbass reddit style “jokes” to reddit. Either answer the question or stfu. You’re not funny and your lame attempt at a “joke” is just annoying.
So mean for no reason.
I think your butt plug has gone sour. Time to change it.
There shall be no mirth in this place!
And yet their “unfunny lame attempt at a joke” got 90+ upvotes, so clearly some people thought it was funny.
You know what I am going to do it even harder dot gif
Plenty of things, but the most obvious being the two separate instances they had issues with renewing their certs.
I think it’s actually 3 now. IIRC they did it again last year
It’s more than that. Broken updates. Failed hardware ventures. The project has been shambling along for a long time.
Don’t forget their package manageer DDoSing the AUR multiple times
You seem to have misspelled package mangler
Oh yeah. Forgot about that one.
and the certs lapsed again after volunteers built tooling to Prevent That
but somebody never set up the cron job to run it
Well that’s confidence inspiring.
Could you please explain why not renewing their certs is such a serious betrayal? Like, if they fixed it, isn’t that okay? And even if it happened again, and they fixed it again, isn’t it human to err? Or why is it such a harsh offense?
Serious question, I don’t know the consequences of not renewing these certs. 😊
It’s the tls certificate that proves your website is legit. Without which, you can potentially be a malicious actor that can pose as the website, and when you download the iso, you could unknowingly download something malicious. It’s pretty hard to forget certificate renewal (most of the time there are plenty of reminders sent and warnings given), so the fact that it happened twice was very impressively bad.
Oh boy. Seems to be the opposite in real life. Especially when it comes to managing stored cert of businesses partners. It has gotten somewhat better now of course, but three years ago most of my company’s sev1 production issues were due to lapsing or unscheduled cert changes.
Can confirm it happens often here too indeed.
People are very harsh with Manjaro. There’s more than just a list of objective facts unfortunately. I suppose there were some bruised egos at some point.
The certs issue wasn’t a big deal, it didn’t change anything for me as a user. It just paints a bad image.
As a former Manjaro user, it has some issues. It has weird bugs that aren’t present in any other Arch-based distro. Pamac ddosing the AUR is pretty bad as well. I’m thankful I used it as long as I did though. It got me hooked on Arch based distros. Everything else feels antiquated now. Actually, Void Linux is kinda cool
it’s the main way for software to verify the identity of a source. without it you let nefarious actors do something like hijack a DNS server and impersonate your servers to your users, which is a pretty big problem if you’re running a software distribution network! it is literally a breach of trust and massive security vulnerability. and it probably broke a ton of shit when software that uses the certificate found an expired one and suddenly (and correctly) refused to work.