US sanctions force The Netherlands off Microsoft and toward alternative NixOS
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
US sanctions force The Netherlands off Microsoft and toward alternative NixOS
Unofficial Hacker News client; not affiliated with Y Combinator.
paulvnickerson · · focus · HN ↗
whizzter · · focus · HN ↗
Besides, technically, if you're chosing an OS in 2026, it sounds like a good plan to start with a system that has many reproducibility, correctness properties and separated packages designed in from the start.
Now, I'm not a NixOS user (altering mostly between win,fbsd,osX and some debians), maybe there's some horrible dragons lurking in using it in practice (do share in that case), but from reading about it sounds like a plan for a system used in a future where people don't need to curse too much about legacy decisions?
mike_hearn · · focus · HN ↗
Nix has numerous properties that make it unsuitable for a normal desktop OS:
(1) It has no concept of libraries being backwards compatible, so if a 200kb core library changes in a backwards compatible way e.g. security hotfix, it will rebuild/redownload pretty much everything you have installed. This kills your ability to roll out security fixes quickly and ensures that updates are far more painful for end users than even on Windows.
(2) Nix advertises its main benefit as being that you can easily roll back bad updates, which is just false. It makes this false claim because Nix treats user state as being out of scope. Try upgrading Postgres across major versions with Nix and then rolling it back and see what happens, or really any program that stores stuff in $HOME and doesn't support rollback. It'll just die, make a mess, and Nix will wash its hands of the affair by saying it did the bit it wanted to do (change the binaries on your path) and the rest is just out of scope.
(3) It has no working concept of native plugins, related to point (1). If two plugins depend on slightly different versions of their host program, they'll just load incompatible libraries into the address space and things will crash.
(4) It cannot run binaries shipped for generic Linux without lots of fragile hacks like binary rewrites. But in the real world lots of important domain-specific programs are shipped as binaries, if they support Linux at all.
erikw · · focus · HN ↗
mike_hearn · · focus · HN ↗
Redownloading everything doesn't protect against supply chain attacks. Those can still happen, no problem.
erikw · · focus · HN ↗