Live data from Hacker News

Fun with Red Star OS

sizeof.cat

31–40 of 179 posts

Re: Fun with Red Star OS

#31
post #23
post #16

Earlier quoted context omitted.

Why are VMs so bad at virtualizing? An ideal VM should be indistinguishable from a real machine. For example a virtualized system running Android should generate fake IMU data, not sit at 0 linear acceleration all the time. And have a real-looking fake IMEI, not a string of 0s.

Hi, virt engineer here. Partly because it a very hard problem (in fact, theoretically impossible if you include timing attacks), but mainly because you don't need to emulate the hardware very accurately in order to get common operating systems to run. Getting them to run is all that we're paid to do, and that's a difficult enough job already. One strange aspect of this is that only a narrow range of current OSes run…

So step 1 is to emulate the world within which the emulated machine exists?

Re: Fun with Red Star OS

#32

Seems more privacy focused than Microsoft and Apple? So sad to even think that. Also, remember that China wouldn’t use Windows 10 due to how invasive the telemetry is unless Microsoft gave them a special version just for China. I’m not saying that NK or China are privacy focused. It seems like even the spies don’t like to be spied on.

As far as I remember the Red Star kernel has a module which modifies all opened images and documents by appending a device fingerprint to the file. In fact it is a chain of fingerprints to trace where the file has been.

So not exactly 'privacy focused'.

Re: Fun with Red Star OS

#33

"The system is absolutely network-silent except when you actively do something that requires network access, like using the browser. It does not call the mothership, not for updates, not for telemetry, not to let Kim Jong Un know the status of your internal organs. Spoiler, he doesn’t give a fuck about your hentai porn. " Take that, Microsoft!

This is something that black-box testing can never really verify. Behavior could be altered by the VM, by detecting that it's not in NK, be triggered sometime later, after typing an entry from a list, and so on.

And it's not like Microsoft gives too much fuck about anyone's hentai porn.

Re: Fun with Red Star OS

#34
> Spoiler, he doesn’t give a fuck about your hentai porn.

These operating systems do actually contain code that add a signature belonging to your install of the machine to pictures and video files, so be wary if spreading your hentai porn in Kim's country because it can be traced back to you.

That said, there's a lot of panic about fears of having it reach out across the internet and infect your entire network without any real basis. If you're comfortable with running Windows 11,you're already sharing more data than the DPRK could possibly want to extract from you, only the DPRK can't use that data and the Five Eyes most likely can.

The Glorious Leader liked his Macbook so he ordered his lackeys to build North Korea their own Macbooks with a shitty font and tracking submitted to their services instead it Apple's.

Re: Fun with Red Star OS

#35
post #13

Earlier quoted context omitted.

> Has anybody found a solution? Frontend designers should stop using remote fonts, or fonts at all, for icons.

And all bad programmers should stop being bad programmers, easy. Maybe if you don't have something useful to add to the conversation, you should refrain from adding anything at all.

Found the designer.

Re: Fun with Red Star OS

#37

Of course this version is now super-outdated. Are there any new versions available?

Red Star 4.0 (2017). Good luck finding it, I haven't.

So far, even though we know Red Star 4 exists and has for years now, it's very elusive with (AFAIK) no disc images yet found.

I think that there was a rumor that it was FreeBSD based instead of Linux based but don't quote me on that.

Re: Fun with Red Star OS

#38
post #11

Is it really necessary to run third-party javascript that "checks my browser" (collects information about me?) before letting me read the article?

The usual method is to let Cloudflare collect that data passively, I like the honesty of letting the user see the DDoS protection in action better.

At least this website doesn't require a captcha when you're visiting through TOR, that's better than most websites behind DDoS protection.

Post reply on HN