5 ms·
Indeed, thankfully using a 9front system from another OS is quite nice. My workstation at home is a Linux machine with a drawterm window open fullscreen. You ca
by moody__ 3y ago
Indeed, thankfully using a 9front system from another OS is quite nice. My workstation at home is a Linux machine with a drawterm window open fullscreen. You can think of drawterm like our version of windows RDP, with a shared clipboard and a way of sharing files seamlessly between the host and the remote system. Under the hood, drawterm is just an implementation of /dev/draw that gets given to a remote system, so you're not forwarding compressed images but individual draw RPC messages. Over a LAN connection you can even play doom at 1080p.
- hollerith 3y agoWhat's the security story like for 9front? For years, Android, iOS, Windows, MacOS and ChromeOS has used a verified boot process that prevents any malware from surviving a reboot in any of the system software, i.e., anywhere except for the user's home directory and maybe other directories created by the user that the user is responsible for maintaining. I don't suppose 9front has that? Also when I used drawterm (as part of Plan 9 from Userspace on a Mac) the drawterm windows had no anti-aliasing, which I might have been able to get used to, except that the native-Mac windows used anti-aliasing and switching back and forth I found a jarring experience (and I was never able to figure out how to configure the Mac (and my browser) not to do the anti-aliasing). (Technically, my browser was doing its own low-level drawing, but it had been carefully tuned by the maintainers of the browser to visually resemble the results of the native Mac drawing systems.)
- deleted 3y ago[deleted]
- eschneider 3y agoAs for secure boot, assuming plan9 can boot from a read-only volume, that shouldn't be hard to implement. The (simplified) way it works on most systems is that secure boot is implement in the SOC and that's used to verify the installed bootloader and then the verified bootloader verifies that the boot volume is unmodified (think checksum, but a bit more complicated to make it boot faster. :) There isn't anything about that that couldn't be incorporated into almost any boot process.
- hollerith 3y agoIf it isn't hard to implement why does no Linux distro besides bottlerocket (specialized for use on AWS and other cloud services) Android and ChromeOS do it?
- stonogo 3y agoDebian, Ubuntu, Red Hat, Fedora, Suse, Arch, Gentoo, and Slackware all support secureboot. After that I got tired of looking up linux distributions, so there are likely more.
- hollerith 3y agoRight but none of those verify /usr like Android, iOS, Windows, MacOS and ChromeOS do.
- stonogo 3y agoThat's not part of secureboot's remit, but distros who do it are generally referred to as 'immutable distros'. Fedora Silverblue, CarbonOS, NixOS, GUIX, Endless OS, and Vanilla OS are a few.
- hollerith 3y agoNone of the distros you list verifies the software installed by the package manager (except sometimes the kernel and the initrd) at boot time and refuses to finish the boot process if the verification fails. I guess an argument can be made that immutability would make it easier to achieve such a "verified boot process", but none of the distros you list has done the work. Also, Silverblue's home page does not even list "secure" or "security" as one of the benefits of Silverblue. (They list reliable, atomic, the ability to revert the system, containerized, developer-friendly, no ads, "all your data belongs to you", and open-source.)