4 ms·
Corporate interests HATE general purpose computing, and the freedom to run what you want. With that freedom, you can hurt their interests by blocking ads, strip
by digiown 8mo ago
Corporate interests HATE general purpose computing, and the freedom to run what you want. With that freedom, you can hurt their interests by blocking ads, stripping out spyware, or avoiding giving up your privacy, and they can't let you have that.
It's a death by thousand cuts that's finally starting to come together:
- Remote attestation like Play "integrity"
- Hardware backed DRM like Widevine
- No full access to filesystem on Android, and no access to filesystem at all on iOS
- No ability to run your own programs at all on iOS without Apple's permission.
- "Secure" boot on Android and iOS that do not allow running your own software
Ever wondered why Windows 11 have a TPM requirement? No, it's not just planned obsolescence.
If they get their way, user-owned computers running free software will never be usable again, and we'll lose the final escape hatch slowing down the enshittification of computers. The only hope we have is that they turn up the temperature a little too quickly that normies would catch on before it gets far enough.
- hparadiz 8mo agoWindows 11 has tpm required to enforce full disk encryption that is pinned to a given machine. Linux would do well to do the same thing. It's possible but almost no one does it.
- dummydummy1234 8mo agoWhat is the benefit of having full disk encryption pinned to a machine?
- hparadiz 8mo agoAnti theft
- vbezhenar 8mo agoThe benefit is to not type encryption password on every boot. TPM stores the encryption key and Secure Boot ensures that the system is not tampered. That said, I think that it's better to use alternative approach. Use unencrypted signed system partition which presents login screen. After user typed their username and password, only user home gets decrypted. This scheme does not require TPM and only uses secure boot to ensure that system partition has not been altered. I think that macOS uses similar approach.
- ab71e5 8mo agoKinda like how I have it set up in linux except the system partition is the uki and the user password is LUKS2 passphrase
- digiown 8mo agoIt is quite hard to do this safely on typical Linux systems, since there is a substantial amount of writable system data (e.g. syslog, /etc, /var). If unencrypted they will leak data, and if encrypted there is little difference from just encrypting the root.
- hparadiz 8mo agoYou encrypt the entire partition with LUKS. Not individual folders and files.
- deleted 8mo ago[deleted]
- ndsipa_pomu 8mo agoA typical linux system will have everything in one partition and even if you do like to split up the system (for historical re-enactment?) it wouldn't matter as you'd be encrypting the whole disk anyway.
- cookiengineer 8mo agoThis whole assumption that TPM is a secure way to store things is ridiculously faulty. It's an interceptable i2c bus, and there's multiple tools available since 0.9 that can recover keys from both cold RAM boot and from interception of the i2c bus. If your laptop gets stolen, the thief also has your keys and can also decrypt the hard drive, which the TPM storage initially was supposed to have been invented for to actively prevent.
- turminal 8mo agoThis sounds like a great way to lose data when the machine dies unexpectedly.
- dgxyz 8mo agoYou can print recovery codes. Just chuck them in your safe. Cryptography is only safe against someone who doesn't come and beat the password out of you if they want it. In my case, only my laptop is encrypted so if I lose it when I'm out it's useless.
- michaelt 8mo agoLinux should replicate Microsoft's feature where they back up your "full disk encryption" keys to your cloud account, completely unencrypted, and share them with the cops.
- notepad0x90 8mo agoThey really should (no joke). That's how recovery works when you manage lots of devices. And I wouldn't be surprised if they can do that with Linux already via Intune. Full disk-encryption doesn't mean your encryption key never leaves the device. Matter of fact, there is no point in FDE if the key is readily accessible pre-boot on the device. And no mature key management system relies on users remembering credentials as the end-all-be-all. Even login credentials have recovery mechanisms. With FDE, that is the recovery mechanism. It helps with locking out disks after a device is lost/stolen. it also helps when the hardware is fried and you have important data that needs recovery. Imagine that but you have 100k devices to manage that way. Are you going to rely on a revolving-door of 100k+ employees to manage that credential? And I'm sure it's stored on disk encrypted in their DB, but eventually the unencrypted credential is needed. Block-ciphers ultimately need the plain-text secret provided to them to function, regardless of what complex systems you use, the ciphers need the same deterministic secret. Ultimately this isn't any worse than being able to go to their website and have a recovery link sent to your email, except instead of the whole send email part, you have to be an authorized admin or owner in their portal, and you just get it from there. Pre-boot, there is no networking or internet, even things like correct time information can't be guaranteed, for more complex systems.
- deleted 8mo ago[deleted]
- madphilosopher 8mo agoGeneral purpose computers, copyright, a free society. Pick two.
- digiown 8mo agoYou wouldn't have a free society for long if the general purpose computers are taken away. The government controls corporations which controls your computers, and with an order all of your devices will be turned against you like the telescreens in 1984. We're already scarily close to that reality.
- franga2000 8mo agoWhy are y'all so scared only when it's the government using the companies to influence people. The companies do it themselves already and in a much more insidious way than any government likely will. You are already being fed propaganda and having your interactions controlled and monitored in order for the people in power to gain more power and stay in power indefinitely. This is already almost 1984. It's just not politicians in power, it's capitalists. How is that better? At least we can, in theory, elect different politicians. With capitalists, that doesn't exist even in theory.
- mindslight 8mo agoIs this question being asked in a way that we actually get to choose? Because the obvious choice is general purpose computing plus a free society. But rather it feels that what is being picked for us is copyright, and only copyright. But really, even picking the freedom and liberty options, copyright could survive just fine as a thing that applies to corporations and other business entities. Individuals could then be left with a choice whether to support their creators or not, which would be a better bargain for many creators without the middlemen taking hefty cuts.
- dTal 8mo agoIs this supposed to be a difficult choice?
- dTal 8mo agoDon't forget an entire new category of computing, AI, which is teetering on the edge of requiring processors from one manufacturer, which in turn requires gigabytes of closed-source runtime. Today, you can do functionally more with a computer with an nVidia chip, driven by their binary blobs, than with any other hardware - even though the application software is usually Free. It's a dangerous situation. We are so used to general purpose compute substrate being "free software friendly", but this amounts to a new type of CPU that categorically requires a closed-source OS to be useful.