[-] unhrpetby@sh.itjust.works 38 points 2 months ago

..without it you cant properly secure the phone.

My understanding is that a locked bootloader helps protect against evil maid attacks and bootloader-level malware persistence. I find this a security risk that I would absolutely take for Google independence. "Properly secure" is subjective.

GrapheneOS do decide what phones they support. It is exactly their choice to support only Google Pixels, rather than taking a security hit for hardware independence (whether you agree with the decision or not).

[-] unhrpetby@sh.itjust.works 25 points 9 months ago* (last edited 9 months ago)

I really like to get some feedback. Have fun everyone!

Remove the "MILITARY-GRADE" stuff. It doesn't relay any useful information and has been used as a phrase in countless crappy products.

[-] unhrpetby@sh.itjust.works 36 points 11 months ago* (last edited 11 months ago)

If such a project were to become compromised (the way XZ-Utils was), it would eventually spread to Ventoy.

What a lot of people don't know is that the XZ attack entirely relied on binary blobs: Partially in the repo as binary test files, and partially in only the github release (binary).

If someone actually built it from source, they weren't vulnerable. So contrary to some, it wasn't a vulnerability that was in plain view that somehow passed volunteer review.

This is why allowing binary data in open-source repos should be heavily frowned upon.

[-] unhrpetby@sh.itjust.works 33 points 11 months ago* (last edited 11 months ago)

For instance, Discord shouldn't be a thing since IRC exists, but Discord exists and is very successful.

IRC lacks a massive amount of features that discord users typically want. Screensharing, VCs with group and camera support, built-in history (don't need to use a bouncer like on IRC), built-in online GIF searcher and sender with one click, huge community of bots that use discord's API to do anything from games to moderation.

It isn't even close.

[-] unhrpetby@sh.itjust.works 26 points 11 months ago

Until we end tipping culture, tip your servers.

If everyone continues to tip by default, then I believe this will delay or prevent an end to the culture. If servers don't have an issue with tipping (because everyone does so), then there is less reason to support change.

If one person doesn't tip:

You're just an asshole.

If a large majority doesn't tip:

Maybe there is a problem with tipping by default?

[-] unhrpetby@sh.itjust.works 28 points 1 year ago* (last edited 1 year ago)

I believe the bandaid needs ripping off.

Just like how community effort into making windows more tolerable never solves the fundamental problem of it being closed-source and out of your control, Firefox being largely dependant on Google, while fighting against privacy invasion and ads creates a conflict of interests.

This is solved by removing the influence

[-] unhrpetby@sh.itjust.works 34 points 1 year ago* (last edited 1 year ago)

Security is much more effective and adopted when it is simple. My understanding is that SELinux is not.

This means not only will fewer people use it and more people turn it off if something doesn't work, it means more people are at risk of misconfiguring their system to allow something they didn't intend to.

This is somewhat mitigated from the fact that, from my experience, Linux Security Modules cant ever make you less secure than without it. But it still can provide a false sense of security if you misconfigure it.

Here is a good article showing what I am referring to, and providing a solid security tool: BSD pledge/unveil on Linux.

[-] unhrpetby@sh.itjust.works 73 points 1 year ago

If you're going to censor something, use an opaque black shape. These half-ass censorship attempts are ridiculous.

[-] unhrpetby@sh.itjust.works 30 points 1 year ago* (last edited 1 year ago)

I'll take a program that isn't getting updates anymore or simply wasnt working in my modified environment using slightly more ram and storage over it not working at all.

I have firsthand experience with videogames made for one flavor of Linux not working on my machine due to dependency hell.

[-] unhrpetby@sh.itjust.works 46 points 1 year ago

This is a good reason for static linking. All the dependencies are built into the binary, meaning it is more portable and future proof.

We don't need flatpak for this!

[-] unhrpetby@sh.itjust.works 30 points 1 year ago

Linus already has a backup. Its Greg Kroah-Hartman.

[-] unhrpetby@sh.itjust.works 34 points 1 year ago

Blanket, emotional statements are harmful.

view more: next ›

unhrpetby

0 post score
0 comment score
joined 1 year ago