The whole Netherlands? What…?
never trust the americans again
I will be so pissed off when a democrat is elected and every single EU country will try to go back to business as usual
I think that’s very likely over. You could argue and people did that one Trump term was just an anomaly. Two is much more difficult to explain away like that and I think Europe gets it now.
Dont worry that will never happen again.
The U.S. imposed sanctions on the International Criminal Court
…fuck this place.
The US or the ICC?
not the ICC.
I can explain a major reason why public services and administration are begrudgingly moving to FOSS or OSS at all. They need to apply security standards like ISO 27001 and when they start going through what the documentation requires they realize that most OSS let alone FOSS make it very hard to have any say in the development of the software.
How do you make sure that the security flaws are patched promptly? Do you open a ticket on GitHub and simply hope it gets picked up by the devs? I can tell you from experience that some OSS devs will tell you to make your own merge request if it’s so important to you. GDPR makes having vulnerable public facing services very unattractive. What about support for the product when you need something fixed or have an issue with running the software?
You can definitely get a license for an OSS, or get a legal agreement for support from the OSS devs for money. I can guarantee you that when managers in public services look at either patching together and managing a bunch of separate OSS or using Microsofts integrated infrastructure, they see the advantages right away.
That is the sad truth… It’s resource intensive and a regulatory problem to create and manage a whole infrastructure. It’s much easier to use integrated and centralized solutions.
Commercial support or if it’s critical enough infrastructure have a full time department/team to do it. Commercial support is the obvious choice for most countries starting out tbh.
Honestly SuSE, Ubuntu, and Hetzner all have good for enterprise support and its crazy that they don’t have more major gov business in the EU now.
But honestly yeah, pay for labour to maintain things. It’s not a breaking new idea. You can do that AND own the things instead of renting from private companies too. Also not a new idea.
The only thing new is that we are talking about computers and we have museums for them already so maybe get with the times, right?
Don’t get me started about ISO. They can go fuck themselves.
But that particular standard doesn’t apply to software. It applies to a company. Its a best practices, audited authoritative report. None of that means the software doesnt have backdoors, flaws, issues, its how they handle them.
Microsoft is a known ISO cheater, and will pay off companies or at least influence them, so I wouldn’t trust ISO or the auditors.
So now, any company that is willing to take on the challenge of being certified can use open source software (which actually is audit-able as opposed to Microsoft’s).
Seems like there is a path forward. Yes they may have to fund a project that helps audit, develop, or maintain critical software. If its open source, you have an entire world could also participate in securely developing software, in the open.
There is absolutely nothing preventing them from hiring a firm to develop a feature in FOSS. Hell, they can even keep it proprietary if they wanted to.
they can even keep it proprietary if they wanted to.
Yes, with the caveat that it would have to be an internal piece of software, or if it’s a public facing tool then it would have to be under a non-copyleft licence. But yeah, for 99% of use cases they could have a proprietary fork.
With non-free software, you have no say at all.
How do you make sure that the security flaws are patched promptly? Do you open a ticket on GitHub and simply hope it gets picked up by the devs?
No you dont expect free labour and pay them.
The problem you point out has been known in the Linux community for literally decades and is the reason why Red Hat Linux was created and any company can, right know, get an Enterprise version of it with an Enterprise support contract.
That said, over the years I worked in seriously large multinational companies which used Linux and other open source products like Apache extensively on the server side (pretty much all such machines had it) so at least on the server side things did change massively from back in the day when companies would get Sun servers with SunOS or IBM server with Minix rather than generic server PCs with Linux due to that rationale you stated.
In fact, it has also become a common thing in much smaller companies, though maybe not the small and micro-sized ones.
The reality on the ground at least on the server side and for infrastructure software is that companies did find a way to deal with the problem of not being able to get support contracts from many of the OSS apps makers, and did so either by just paying some company specialized in supporting it or by having their own developers - after all, it’s exactly the thing with OSS that any developer can change it hence you’re not limited to paying for support from a specific company that makes the software.
Well fuck, if it so hard for them to do it, they can hire me and I can implememt DISA for them. They’ll nees to bring in an old immigrant though.
I’m in a local administration in France, it’s rapidly getting closer to home… Our higher-ups somehow decided a thourough Microsoft integration was a good idea like 5 years ago.
Seems like we’re just one political comment about support to the ICC to be in the same situation. And I mean, fuck it, we should be. But I am not happy about the shit we’ll have to go through to purge it all now.
If I can sell my house, I’ll do it. But I’m in the US. Sure do want out. My house has been on market for 5 months.
I’ve been doing a project https://themildtake.com/articles/2026-07-04-a-declaration-of-independence/ ever since Independence Day and I have been shocked by how insane the open-source tooling out there is now. NextCloud and Collabara alone solves 90% of company’s needs. ERPNEXT covers a huge swath in mid-range needs. I combine it with a mailcow server and Authentik for SSO and I am not sure how much else most businesses need. The whole stack is zero cost.
Foreign countries using Google, Microsoft, or Apple, would be suicidal not to change platforms. Right now, the U.S. has incredible leverage: it can turn off their government servers, delete their data, and is certainly spying on them right now.
The only reasonable move is some kind of self-hosted setup, at least for a large chunk of critical infrastructure, with some cloud options for backups, maybe, who knows, if the country is too small or centralized.
I am in a large (couple thousand staff) company and I cant get why we dont selfhost everything. Like yeah it would have an upfront cost but the savings stack immediately. We spend like 30-50 a user for office access.
Copilot is so shit and we could build an alternative with relative ease and never pay again. It wouldnt be baked into teams but who gives a fuck.
Yay Broadcom or something.
US: You want to cut us off? No! We cut you off!
NL: How petty are you?
US: Yes.
Considering the Dutch have ASML, this seems an unwise move for the US. But then, the Dogey Confederates are working towards the destruction of the USA. 😒
deleted by creator
Not OP, but I don’t understand your question.
As a US citizen, I try to say “The States” instead of America when talking about my country. I do that out of respect for all of the countries that call these two beautiful American continents home.
I admit to defaulting to “American” instead of a cumbersome “United Statesian” or the above “US Citizen.” But that’s what we grew up calling ourselves and told to call ourselves and our fellow countrymen.
“Just another American Country” seems like it would be insulting to Canada, Chile and all of our neighbors in between. I’m not sure my fellow Americans would even pick up that you were talking about the States unless you really layed on thick context.
Considering the Dutch have ASML,
That’s a card which only hurts ASML if played.
If ASML has many competitors, then yes.
How much asml machine in the us rn ? That s not how stuff work
Tell us, how does “stuff work”? What up and running alternatives do the US have to ASML machines for latest generation high performance silicon? No matter where.
Look at asml client. Either us or Taiwan. They can’t skip that market. U dont have alternative to asml yet but asml has no alternative for client either. Also fab are long term devlopement thoses contract are already lock. And asml play by american rule regarding ban export and so more. Asml is never gonna ban the us. The us can but it serve them no purpose. Asml is a public traded company. If u think they gonna loose their biggest client… Idk what to say but that s unreal
ASML plays by US rules as long as things don’t escalate badly. Your arguments only work during nice weather. When things get tough, ASML is squarely located in the EU and will comply with local laws and law enforcement. That is a substantial risk for the US if it were to go for all out economic warfare, like forcing Microsoft to boycott EU customers.
Of course ASML has no interest in such a thing, nor does Microsoft. The Single Market is a very big market for Microsoft. Also, blowing it up would not just pulverise that market, it would lead to a collapse of most of the business outside of the US in the mid term.
So first part of your argument is saying it can happen and second part is saying why it won’t happen. Yeah I agree it won’t happen. And ms sell service wich isn’t the same as the fucking lithography that power everything advanced under the sun.
Ps : second time you intervenir on my comment to say I’m right by prefacing I’m wrong. Kinda funny. Waiting for the third time
You either deliberately misunderstand my arguments or really misunderstand them. The companies don’t want that of course, but it is not entirely in their control. The EU certainly doesn’t want it either. Regarding the US, it really depends. It depends on how much the strongman in DC fears that the other side can actually retaliate. A nuke’s value is not that it destroys everything, its value is that it could destroy everything. Russia would not have invaded an Ukraine with nukes, yet Ukraine would likely never used any nukes even if it had them.
Of course ASML is not the only economic nuke Europe has. If the US unleashes economic nukes on the EU by for example forcing Microsoft to block many or most services over night, the first response would be to threaten nuking the USD, with a believable threat scenario, but ASML would be a backup option.
This might just be the best thing that happens in tech (for me) all year.
I daily drive debian just because boring and reliable. However, fancy package managers like flatpak and appimages and nix have made debian much more vibrant - it’s easy to install new versions of things now.
That said, nix package manager on debian is just freakin amazing. Being able to just
nix-shell -p <obscure cli tool>andexitwhen I’m done with it is magnificent.That’s the gateway drug anyway. The nix based home-manager is pretty cool.
While I’ve been tempted to jump in with NixOS my experience with nix packages and home-manager has felt kind of bleeding edge or experimental. Loads of things that don’t work as intended on debian.
A sophisticated well funded user base like a federal government has really good implications for the stability of the project in the future. I’m really stoked about this.
NixOS is great, but it definitely breaks things. It’s the way it works, though, not whether the software is bleeding edge. Nix lets a package specify its own dependencies, even if those dependencies conflict with those of another package. It does this by breaking the traditional POSIX file system structure that many programs assume they can depend on. It puts all sorts of things where they “don’t belong”, and then uses a small army of environment variables, scripts, and symlinks to stitch it back together so that no individual package realizes what happened. If you only use software from the package manager, this is often (but not always) seemless, but if you download stuff from the web, none of the system libraries it traditionally expects are there. Likewise, if you’re using Nix alongside something like Debian’s apt, I wouldn’t be at all surprised if the two package managers doing things in two different ways causes some issues that are hard to interpret to the uninformed.
Personally id say try it in a VM*. Home-manager and nix packages (and even flakes at this point) havent felt like experimental features for a good 5 years for me on NixOS
Edit: while on Mac yes. Havent played with it that much on other distros
US has been building soft power like this for decades, and Trump is pissing it all away.
If this process to get rid of dependency on US gets well underway, there’s no turning that ship. US won’t recover the position it had in fifty years or more.
I’ve been pro US imperialism for a while now, but honestly I’m glad that the rest of the world is shedding the worst of our power projection.
On one hand the heel position has really pushed a lot of the world in a positive direction, but there’s gotta be a better fucking way then, like you said destroying half a century of international relations and cooperation. That’s not to mention the bigger issue of US supported genocide in Palistein and the ethnic cleansing operation in the states, which I can’t excuse for any 4d accidently good things on the geopolitical scale.
US won’t recover the position it had in fifty years or more.
This is not a bad thing. Over dependency on any one nation or even a bloc of nations is a bad thing.
I can’t help but think the dependency on the US that has been created played some role in what’s happening now.
Honestly, I can see that. America has been top dog for so long, it doesn’t value what it has.
Not even that. I’m thinking too much money, power and influence all consolidated in one place.
The US has the most billionaires at 989 and I’m guessing of the remaining ~2400 billionaires in the world, a not insignificant amount have substantial interests in the US.
It’s good the rest of the world is watching it happen. I hope they’re taking notes because it’s not stopping in America.
Well of course. The whole point of US trade policy was to maintain global dominance. You don’t think that politicians were sending money to other countries purely out of the goodness of their own heart, do you? … Of course some of them have good intentions some of the time, but let’s not pretend no other reasons came into consideration.
Nope. The US isn’t teaching people to fish, its forcing them to learn How to to feed themselves. In the past they handed them the fish so they could control them. That power is lost now.
US: Let’s sanction everyone everywhere all at once!
Also US: Why don’t people want to be dependent on US systems? 😭
Couldn’t undermine the country more if they tried, which makes one wonder.
Yep. Trump’s actions are no different than what any bad actor would do if they wanted to destroy the USA without invading it.
- Destroy our soft power… check!
- Turn allies against us… check!
- Destroy our economy… check!
- Drastically weaken our military… check!
Destroying what (appearance of) democracy they had as well
And I’m accepting that he does it because he’s likely a Russian asset, but why the fuck are the rest of them playing along? You can’t tell me they’re all being bought.
They want corporate slaves, if the us is governed by the rich and corporations, corporate cities/islands they are trying to build are not needed anymore.
Yea we got a bit of the “inmates are running the asylum” situation over here.
In the immortal words of the joker(paraphrased) this country needs an enema
we would lose about a third of our human biomass
Oh well
I wish. Organizations and countries/municipalities are far too lazy to make the change.
The time and money involved are both staggering. This isn’t about you switching operating systems on your personal laptop.
Where are you going to get support staff anytime soon? All those Windows admins magically switching to Linux overnight?
Hell, Linux offers nothing remotely comparable to the power of Active Directory. That alone will keep Windows in the lead.
And more. This isn’t about lazy.
Time + motivation + money can overcome a lot of obstacles. It also helps that template of what is needed already exists in Active Directory. This changes the project from “innovating something new” to “a slightly better copy” and is usually a lot faster and easier.
All copyright/patents are also void because of the sanctions at least in practice.
I have worked in big company where linux and windows coexisted, but we were developers so maybe that’s why (IT was very strict though).
What is the alternative to AD, and are there currently companies running that, big or small?
At this point, a lot of entities don’t need AD because their entire workflow runs in a web browser, and practically any SSO provider will work.
That said, accessing actual computer resources can be managed with groups and ACLs. Perhaps not as elegantly or as well-integrated as AD is, but that’s the price you pay.
I replied elsewhere, but our org has just been so happy with Jumpcloud.
Red hat IDM, aka freeipa.
Depending on what youre doing you absolutely don’t need active directory.
Hell, a lot of orgs are just going entra anyway. If you’re using SSO like that or okta or keycloak you likely don’t need AD.
Windows is basically a zombie OS at this point, shambling along and eating brains.
Windows as a home user desktop is definitely coasting on momentum, though it is also the OS deployed on most new PCs which keeps it going.
I think the only thing really keeping Microsoft relevant is Active Directory (and Azure by extension) because a lot of organizations are dependent on AD internally, and there still aren’t really any good alternatives that check all the same boxes. You could probably cobble together a working solution for ~90% of it with open source software, but it would be clunky, fragmented and feature-poor compared to an on-prem AD system. It would require a lot more administrative overhead to configure and maintain it, and user management would be a mess.
I’m starting to see non-AD companies cropping up. If you have to support Mac and Mac is absolute trash on AD, you need to run software to manage the macs which can already manage windows. With all the remote work, even RMM software is on the rise.
EntraID also seems corporate established. For a modern with system, with zero trust etc, you use EntraID instead of AD now.
Of course, legacy AD systems, if they exist, are also lock-in.
Over 10 years ago I deloyed Zentyal, which is a Linux OS that works as a drop in replacement as a domain controller. Active Directory, Outlook mail server and file server out of the box. I can only imagine it got better.
EntraID is just a rebranding of Azure AD
Azure AD, the cloud version, still isn’t as feature-complete (or possibly feature-bloated) as the original on-prem AD, which is a big reason large organizations won’t switch away from it.
AD is a security nightmare. EntraID requires internet but at least allows zero trust with diverse configuration and importantly without storing or holding session tokens or passwords locally.
For my company, the only blocker is file share, which can be migrated. All our with integration use ldap and can be migrated to openid. Luckily we don’t have more AD integrated stuff.
Sounds like there’s a startup opportunity here.
Sure, but they’ll have to catch up on almost 30 years of feature development (and feature creep). Active Directory is entrenched, by virtue of being the only game in town for decades.
Not that they’re necessarily irreplaceable, but… a half-competent Windows Server admin can go from cold iron to running HyperV with a local domain (AD forest) with a SAN supporting 200 endpoints (assuming the hardware is already in place) pre-configured with end-user applications and all relevant network & security settings (via group policy), with a print server supporting local network printers, and be ready to enroll new users, in less than a day.
I’ve seen it done, I’ve helped get it done. And all of that can be done with point-and-click GUIs, and not a dozen different ones, just like 3 (one for server/HyperV deployment, one for HyperV config post-install, and then basically everything else can be done through Active Directory).
When you’re a sysadmin for a large organization, that kind of operation at scale is non-negotiable. When I say that AD really has no competition, that’s what I mean. You could accomplish all of the same things on Linux, but it would take you a week of punching through terminal commands just to get the server and the domain up and running, and once you were done the user management still wouldn’t be as flexible or feature-complete as it is on AD (especially if you need things like auditing, or physical access token integration like badges for authentication, or remote desktop support, or video conferencing that is linked to corporate email accounts).
All of that said, if you happen to know of a group that’s actually working on a competitor for on-prem AD (not Azure AD/EntraID, the cloud system is very different and not really comparable) I would be very interested. It’s a problem that’s been on my mind for awhile now, and I’d love to get paid to actually work on it.
Hey I didn’t say it would be easy, you’re right there’s a ton it’s doing.
Rebuilding what it’s doing though wouldn’t take 30 years, they’ve figured out the requirements which means a startup can start fresh and build something even cleaner that works full on premise but seamlessly leverages cloud services if you want them for backup / recovery situations in the event that your on premise systems have a failure.
I don’t know anyone working on this but the fact that it would be hard means it’s actually not easily replicable and would be a good business for a startup to capture. The value prop is high for companies, if they could save a huge amount of money on licensing and get improved operational cost without sacrificing what they get from on premise it would be worth it.
It would definitely be hard to get companies to switch but the potential savings and country independence parts might be enough to make them interested in paying the switching costs.
Not to even mention the biggest of elephants in any MS room - Exchange.
You should check out JumpCloud. It frankly feels a lot like you’re living in a cloud-first, Microsoft-free future. It’s a dream to use and scales, manages Windows, Mac and Linux as equal citizens. We don’t even maintain on-premises servers (including domain controllers) anymore, we just use IP addressing from the firewall and patch, control, manage all our computers from one pane of glass.
living in a cloud-first, Microsoft-free future
Oh really, whose cloud? Oracle?
We don’t even maintain on-premises servers
Ah, you’re dependent on someone else’s computers, someone else’s network architecture.
That sounds awful.
Nope nope nope, need on-prem only data, on-prem user account control, on-prem domain, absolute positive control of all outbound network connections with as few of those as possible, and no dependence on someone else’s monthly compute fees.
Local always, remote only when absolutely unavoidable, and then stripped to the bare minimum. I’ll run my own NTP server so that only it has to reach outside for time updates, and every other local device can get time from it.
NO. CLOUD.
It’s fine to have these feelings, it just depends on your comfort level. For my home / personal life, I agree very much. For business, not so much (but, depends on your business).
OK, maybe no cloud is a bit extreme, I’ll grant that. Maybe your business needs some clunky, minimum-effort, rent-seeking SaaS crapware like Salesforce… fine
IaaS? No. Nope. Not for anything we actually need.
No cloud for anything required to manage and maintain the local network or user accounts. If the external network goes down, we’re still operational internally, we have our own domain and authentication servers, everyone can still login and run any locally deployed applications (which we prefer, so most of our business needs are served that way). We’re not going to lose corporate data to the latest AWS leak, we’re not going to be dead in the water because AWS East went down again, we aren’t going to have to reasess our budget because AWS raised their monthly fee again.
It’s not about “feelings”, it’s about proper risk assessment and mitigation.
You can outsource labor, you can outsource storage, you can outsource compute, you can’t outsource risk.
For business you should be able to fully control the VM, back it up and restore it somewhere else.
If you can’t do that ypu are chained.
I heard OVH is at it. Maybe among others.
All middle powers need to align and collaborate on this. There is limited programming talent and gaps and especially security (ai) gaps need to be filled. EU, UK, Canada, Aus, NZ, SK, Japan should actively pool resources.
Finally. Been saying for years, NixOS is the obvious choice for a gov distro.
Now we need to convince Canada to do the same. If everyone leaves Microslop, that would make a huge impact.
I am curious, what makes NixOS such a good choice?
From the article:
Its use of the Nix package manager means that each package is installed in its own directory with immutable and signed contents. That alone means that the setup is incredibly easy to reproduce across multiple machines, something that is an obvious benefit when dealing with different facets of a government.
Id argue an immutable distro would likely serve the same purpose but maybe its also because nixos isnt as “locked down” so itd be easier to configure for a specific purpose?
The big draw is probably that it’s declarative, so you can define installations as code much the same way as you would do with Terraform. Instead of needing a pile of messy Ansible playbooks running custom scripts to change anything (and which can break if the target machine has an unexpected config), you’d just have one that pushes a new version of the config and runs nixos-rebuild. Rollbacks are just as easy if anything breaks. What’s not to like?
Right so in that way, its very reproducible. That was my understanding and I appreciate you for the more in depth explanation but is there advantage to that versus an immutable distro? Wouldn’t a immutable distro work in a similar way being reproducible among many machines?
Rollbacks can be done on immutable distros as well right? I’m just curious why Nix was the first choice and not something immutable.
Thanks. I read Smiletolerantly’s comment as a personal opinion, rather that a summary of the article. I read several articles in Dutch news outlets, but the main message was ‘hurr-durr-Dutch’.
nix is on a whole different level than silverblue and other ‘atomic’ distributions.
But not curious enough to read the article.
You know, you could simply be helpful.
Sure.
It’s in the fourth paragraph, starting with
From a technical point of view…
and ending with
… would usually balk at.
Why?
Honest question.
My guess would be the deterministic configuration management. If it’s for a personal machine then do what you want to make it your own but if it’s an organization (e.g. government) you want the machines to be as similar as possible to reduce maintenance. Think cattle, not pets.
Ansible is a thing though. It is also a more complete, mature and easily substitutable solution vs pinning your hopes on a single distro.
Programmers like NixOS because they are programmers.
Ansible is US-owned. Even though it’s open source, Redhat, a US company, is the one that controls its lifecycle.
NixOS is based out of the EU.
Fun fact, Nix, Nixpkg and NixOS have their roots in the Netherlands. For example, Nixpkg was even described in a PhD thesis at Utrecht University.
Aren’t Nix repos hosted on GitHub which is owned by MacroSlop?
I mean they sort of serve different purposes. You can build a NixOS ISO running your exact desires configuration that is good too go immediately upon install. Ansible would require post install configuration, yes it is scripted but it is additional overhead and time. I think a better alternative would be an OCI based distro with a Packer build pipeline, which could include Ansible steps higher up in the build process. But that’s more complexity that Nix wouldn’t require
i used ansible some years ago and i’m using nixos currently and you can not compare those two.
i was not fluent in ansible and i’m not fluent in nixos. yes you have to leave your comfort zone for nixos, but your get so so much more.
the jinja templates in yaml feel like a big hack if you used nixos.
would really be interesting to hear someone talk who is comfortable to use both of them.
I’m honestly amazed ansible still exists. I used it regularly like 10 years ago and never liked it. I use NixOS for all my servers and package all my code as nix flakes, and I agree that they’re barely comparable.
NixOS is a kinda frustrating desktop distro to me though. Sometimes you just wanna type
make
It’s close, but Ansible is often not deterministic.
from a sys admins perspective it’s painfully easy to deploy across hundreds of machines. NixOS is declaritive and immutable. you can take one system configuration of NixOS and throw the same config on as many machines as you want. packages, dotfiles, whatever are all replicated the exact same way on each machine. You can lock all the packages/apps, configs, kernels, etc to a specific version therefore a sysadmin may only need to upgrade the lot once a year. if a user some how breaks their system it’s as easy a fix as rolling back to the previous generation with a single menu option.
So basically say you have your computer and you want to replicate your exact setup to hundreds of other computers. with NixOS it’s as simple as setting up a git repo for your nixos config, pushing to it, installing nixos on every other computer then cloning your repo to all the machines and rebuilding. done. now you have hundreds of other computers that all behave and work the same way your computer does.
If something needs updating or a fix needs to be rolled out all a sysadmin has to do is fix it on one machine, push the change, pull it for every other machine and rebuild. done.
Or just configure all the machines to auto-update from the flake at the repo. Doing this for my VMs. I have a CI machine that builds my pinned flake from the repo tip, and about 30 other VMs check nightly if the repo tip has moved, and if so, rebuild from the new tip; which, thanks to the CI machine, means just downloading and activating a new generation, nothing compute heavy.
The only thing is this doesn’t yet do online user directories, local users only
Which is a big constraint right now













