Earlier quoted context omitted.
It’s already happening. Many big institutions lean heavily on mobile apps and other gated computing. I live in BC Canada and by far the easiest way to authenticate a login to provincial sources involves using the BC ID App as a second factor, even when logging in via desktop. Many banks now also use their app as a second factor, rather than a generic OTP option that can run on any hardware. There were also issues lik…
> Many banks now also use their app as a second factor, rather than a generic OTP option that can run on any hardware. This is one I’m willing to tolerate, as long as it’s optional. Something I don’t understand though is banking app setup. When I got a new phone this year, the RBC app made me submit some kind of live selfie. The thing is, I know they can scan your debit card with NFC and authenticate the PIN. I’ve us…
What happened to running what you wanted on your own machine?
241–250 of 315 posts
Re: What happened to running what you wanted on your own machine?
#242It's important to understand that we could genuinely lose general purpose computing. I don't think it's in serious danger at the moment, but we've been in the midst of a slide in that direction for the last 10-15 years. Part of it is mobile phones, part of it is TPM, part of it is market forces. The latest turn is strictly political. We've really foolishly built the technology necessary for authoritarianism just a fe…
Death by a thousand cuts. TPM, secure attestation, age verification, DRM, and probably more things I'm forgetting right now.
Re: What happened to running what you wanted on your own machine?
#243Earlier quoted context omitted.
Raspberry Pi and clones/alikes are ARM devices with perfect Linux support.
Raspberry Pi is one of the least open platforms around. Broadcom SOCs preferred by Raspberry Pi require proprietary blobs to function, and much of their functionality is buried under a mountain of NDAs.
Re: What happened to running what you wanted on your own machine?
#244I believe that in the depths of the cold war, when personal computers were just showing up, it was decided, deep within the National Security Agency,that it was more advantageous to let them continue to proliferate without fostering secure Operating Systems, though they were available. We all now live with the blowback from that decision. Most people don't even realize that actually secure computing is a possibility…
I affirmatively argue that actually secure computing is not a possibility. It's fun to build toy models where every process has exactly the permissions it needs and no more, sure. In the real world, your users are going to grant superuser/admin permissions to random installers, and they're not going to perform the complex verification rituals you told them to do beforehand. It's like trying to set up a warehousing sy…
Re: What happened to running what you wanted on your own machine?
#245Earlier quoted context omitted.
No, the issue is too much of the Secure Boot chain is currently being controlled by Microsoft. Kernel being GPL has no point currently. Require hardware attestation with Microsoft private keys + systemd-boot + systemd + uutils can create a nice walled garden, allowing "vendors" to build locked-down hardware-OS pairs. More importantly, uutils is MIT, which can attest at every level, without sharing a line of source co…
Uutils is literally one guy's self-tutorial to learn Rust. The fact that it's breaking Ubuntu has more to do with that than some shadowy conspiracy.
- 22K stars
- 1600+ forks
- 33 releases
- 622 contributors
- 678 users (at minimum)
- Code of conduct (with a debian.org mailing address nonetheless)
- 1 distribution shipping it as default (so far)
The project has the stated goal as follows [0]:> The uutils project reimplements ubiquitous command line utilities in Rust. Our goal is to modernize the utils, while retaining full compatibility with the existing utilities. We are planning to replace all essential Linux tools.
This is hell of a self-tutorial.
If this was GPL licensed, I'd love to try these. But at this point, it's looking for pushing GNU out of the Linux ecosystem, completely.
Re: What happened to running what you wanted on your own machine?
#246Earlier quoted context omitted.
If the victim really was coerced/forced, then there is no wordplay going on here. No legal tricks. No abuse of the legal system. We're talking about sex trafficking, which we know did occur and Epstein was convicted of. Twice. And possibly rape/sexual assault, even though the "perpetrator" did not know about it. You're getting awfully close to defending Epstein there. I also can't help but notice that you ignored eve…
> If the victim really was coerced/forced Coerced/forced by whom? Are you actually stupid or just pretending?
Re: What happened to running what you wanted on your own machine?
#247Earlier quoted context omitted.
I think it is unfortunate how many resources are put into making things secure with TPM's and how little resource is put into basically having secure and simple sandboxing... All I really want is a computer that allows me to fully control the permissions and filesystem access of all the programs that I manually install on my system. Almost every program (in my case) needs 0 filesystem access outside of what it instal…
Another simple permission is network access. Why can't I restrict, say, a calculator app from accessing the internet on either iOS or Android?
Re: What happened to running what you wanted on your own machine?
#248Earlier quoted context omitted.
> If the victim really was coerced/forced Coerced/forced by whom? Are you actually stupid or just pretending?
What do you mean by whom? This conversation isn't about Mickey Mouse. Epstein was convicted for trafficking (eg. coercing/forcing) women.
Anyway, I get that you're confused. However, I've lost interest in talking to you.
Re: What happened to running what you wanted on your own machine?
#249Earlier quoted context omitted.
Passkeys are another brick in this wall. The authors of the spec built in client software identification and attestation, which means authenticating parties can require you to only use certain, closed-source passkey clients. It's not hard to imagine a future where only blessed Passkey clients, such as Microsoft's, Apple's, and Google's implementations, are allowed by most services.
Password managers are regulated as "important" software under EU CRA (Dec 2027).
Re: What happened to running what you wanted on your own machine?
#250What would you include?