4 ms·
> Personally, I don't really care either way. Perhaps you need to consider the possibility that the battle between systemd vs sysv init is not unrelated to the
by dane-pgp 4y ago
> Personally, I don't really care either way.
Perhaps you need to consider the possibility that the battle between systemd vs sysv init is not unrelated to the desire of Microsoft (and others) to lock down general purpose computers.
By giving Linux one tightly-coupled system that controls everything from the boot process to process permissions, it becomes much easier to add the missing "features" needed to implement such a lock down (and harder for distros to support "non-standard" configurations which slow the adoption of this).
This probably already sounds like a conspiracy theory, but I absolutely believe that intelligence agencies are eagerly awaiting the day they can convince governments to ban "insecure" computers from going online, where "insecure" means "not supporting Secure Boot attestations and not supporting an app blacklisting service like Gatekeeper[0]".
The existence of Linux (especially non-mainstream distros) is an impediment to a government introducing such a law right now, but if 90% of Linux users are running systemd, and users can install some future "systemd-gatekeeperd" with a couple of clicks, then no government will hear the cries of the greybeards who refuse to configure their machines this way.
Once the law is in place, the loopholes for distributing and running "unapproved" code will be slowly closed one by one, meaning fewer and fewer people will have access to apps/protocols like Tor, BitTorrent, E2EE messengers, and VPNs (unless those apps/protocols also include endpoint blacklists and do client-side scanning for illegal files).
[0] https://www.pcmag.com/news/apple-explains-why-it-grabs-data-from-mac-computers-amid-privacy-concerns https://www.pcmag.com/news/apple-explains-why-it-grabs-data-...
- none_to_remain 4y agoThe push for everything to go to HTTPS feels like it fits in here. I'm envisioning one day your browser just doesn't speak unencrypted HTTP and you can no longer bypass warnings for untrusted/self-signed certificates. You can't use a better browser or install/remove certificates as you please without illegal jailbreaking.
- dane-pgp 4y agoI'm not quite sure what the threat model is that you're suggesting. Are you imagining that a government will demand that browsers drop support for unencrypted HTTP? It would be simpler for that government to just demand that ISPs drop traffic on port 80 (or do deep packet inspection for a slightly more sophisticated approach). But in any case, what's the danger with that? Are you worried that a government could tell all CAs not to issue certificates to "subversive" websites? Obviously there are jurisdictional problems with ordering CAs in foreign countries not to issue certificates, but I suppose a government could instead require that all browsers (within their jurisdiction) only trust certs from the government-run CA. Those would certainly be bad outcomes, but if your threat model includes "the government controls what your browser can do" then I don't see how the situation is any worse due to widespread adoption of HTTPS. If the government is going to interfere with your browsing, then it's actually some consolation that other random attackers aren't also able to do that. The only extra attack I can think of that mandatory TLS makes possible, is that this government which controls its citizens' browsers in this way could then put pressure on Let's Encrypt (via the US government?) to require ID information from all their users (and a similar rule for other CAs, which wouldn't be too hard as most of them require non-anonymous financial transactions). That still seems like a lot of unnecessary work for little benefit, though, surveilling web publishers when this government already controls its citizens' browsers.