Hacker News new | past | comments | ask | show | jobs | submit login

Something I think is a bit misunderstood here is what this is for, and why it was made.

The person who wrote this (aszlig) is truly a hacker, contorting tools to do interesting things -- and indeed, you see his cleverness at work here.

This is an update script, which is run by hand, by a maintainer, to update the Nix expression for Chromium.

This script could have been written in Python, Bash, Perl, or PowerPoint for all it matters. Or even Brainfuck using aszlig's own brainfuck interpreter written in bash[0]. This script could be deleted today and make no difference to using Nix. It is not part of any running system.

This doesn't mean Nix is insecure or broken, and no abuse like this is used anywhere in the Nix package set.

[0] https://github.com/aszlig/shellfuck/blob/master/bf.sh




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: