People talk about "noncustodial" and "open source" but they love to use these hosted Docker images they didn't build or verify.

Reply to this note

Please Login to reply.

Discussion

Raspibolt and derivatives all the way here

Practically no one builds their own binaries or APKs either, that's not the point of FOSS.

The point is that you can at any time reproduce the resulting image or binary from the code and can choose to go the extra mile and compile it all yourself.

Using hosted images is well worth it the vast majority of the time for simplicity, but Docker also makes it trivial to compile locally as well.

It's like chewing gum you find on the street and thinking you're flippin' Willy Wonka.

there is always a spectrum , is good to be able to have the option and choose , do you bootstrap your libc ? 😉

closed source custodial is the way

Are you Bill Gates? You kinda look like Bill Gates.

I actually lol’d

Happy pi day to you too!! #[3]​ 🍕🍰🥧

Fiatjaf woke up and chose violence

Don’t verify don’t trust don’t do anything

If everyone built and verified every piece of software they ran themselves we would only have time for about 10 projects to exist

haha love when they don't even pin the image hash

They also tend to use CPUs where they didn't check every transistor under electron microscope

Any problem with using those images on a home-server in your opinion?