• 1 Post
  • 22 Comments
Joined 2 years ago
cake
Cake day: March 28th, 2024

help-circle
  • To be fair, he did a lot of experimentation and that builds up his pantry and spice rack over time. His latest video about eating for $10 a day basically limit his spice selection too. And again, the takeaway from him is always to learn how the flavor actually combines rather than specific recipe. So you know when it is fine to substitute beef with pork for example and when it is not


  • This is why I like Ethan Chlebowski. He advocate to not learn recipe for home cook but straight to the basic. How to combine and mix ingredients so you can eat well with whatever you have. After you have build up those basic, then you can look at recipe so you know what can be substituted with what you have, and what you really need to have and buy new. Along the way, hopefully you’ll also be more proficient in using your knife which constitutes most of the prep time



  • Contractual obligations cannot override laws does not mean the law is not legally binding. It just means that a contract cannot be put on an equal pedestal as a legal basis since a law can override it. Say a consumer protection law states you have a warranty that is tied to the device and not the purchase. But then the manufacturer put ToS/contract clause stating the warranty that comes with the device must be accompanied by sales receipt as well as the warranty card. Those clauses are not legally binding and if the company doesn’t honor the warranty, you can sue them for breaking said consumer protection law instead







  • I know where you’re coming from when you say they are different. But I disagree on that because at the end of the day you’re still trusting other people would not act maliciously or get their account compromised. The selection process doesn’t make it any more special as demonstrated by xz in my example.

    Anyone can be an AUR submitter and maintainer. Act in good faith and never become an Arch maintainer. Someone can be an Arch maintainer and be good for a few years then something happened and their account got hacked or bad blood made them act rashly.

    That’s precisely what I mean when I equate AUR maintainer to the distro maintainer. To the package management system, they are both trusted. Not in the sense of how special they are or how strongly you can trust one but not the other.


  • Yes, and that is no different than distro maintainer that maintains the infrastructure and package. Anyone can volunteer. That’s how xz is compromised. The point is that aurto trust models mimic those of other package managers. Trusting the authors implicitly trust the code. The only other special things from distro maintainer is their PGP signatures are required to perform release on the main repo. This is better because as I stated earlier, reviewing PKGBUILDS would encourage people to just skip it. Not everyone has the time for that. But when a maintainer changes? Aurto removes the package for you to perform that first trust again on the new maintainer. This is no different than if you update the arch keyring just more manual