4 ms·
Both systemd and dbus have a similar device id for Linux, which e.g. Chrome reads at startup: https://manpages.debian.org/trixie/systemd/machine-id.5.en.html h
by tremon 3mo ago
Both systemd and dbus have a similar device id for Linux, which e.g. Chrome reads at startup:
https://manpages.debian.org/trixie/systemd/machine-id.5.en.html https://manpages.debian.org/trixie/systemd/machine-id.5.en.h...
https://manpages.debian.org/trixie/dbus-bin/dbus-uuidgen.1.en.html https://manpages.debian.org/trixie/dbus-bin/dbus-uuidgen.1.e...
- givinguflac 3mo agoIs this specific to Debian?
- tremon 3mo agohttps://www.freedesktop.org/software/systemd/man/latest/machine-id.html https://www.freedesktop.org/software/systemd/man/latest/mach... https://dbus.freedesktop.org/doc/dbus-uuidgen.1.html https://dbus.freedesktop.org/doc/dbus-uuidgen.1.html
- cryo32 3mo agoFreeBSD has it as well.
- nickjj 3mo agoNope, but Debian does use systemd by default so it's there. I'm running Arch Linux and /etc/machine-id is present. There's also an optional /etc/machine-info file that could exist. It's not a part of systemd and won't be created by default. It's more of an informal way to have details about the system in 1 spot. It was more popular when provisioning bare metal servers but still has value in the cloud. You can have key / value pairs on who to contact, where it's located, what type of machine it is, etc..
- heikkilevanto 3mo agoI don't like the idea of a persistent id for my machine. Would there be any harm in rewriting the machine-id at every boot? Or just deleting it as part of the shutdown sequence?
- gcr 3mo agoThe supported method to get a new one each boot is to truncate the file to 0 bytes and disable systemd-machine-id-commit.service Double-check that this method actually works though. Machine ID is used for things like dhcp leases, log rotation, etc. IPV6 addresses or transient MAC addresses are derived from it
- inigyou 3mo agoI thought the kernel generated SLAAC addresses based on MAC and privacy addresses based on random numbers.
- tremon 3mo agoIt does, but DHCPv6 prescribes a persistent device identifier (DUID): https://www.rfc-editor.org/info/rfc9915/#RFC3315-9 https://www.rfc-editor.org/info/rfc9915/#RFC3315-9 The DUID is designed to be unique across all DHCP clients and servers, and stable for any specific client or server. That is, the DUID used by a client or server SHOULD NOT change over time if at all possible; for example, a device's DUID should not change as a result of a change in the device's network hardware or changes to virtual interfaces
- xeyownt 3mo agoWhatever you do there will always be uniquely identifiable information (if not an id, a fingerprint) on your machine. If you want to escape that, you have to use dedicated privacy-enhancing tools / browsers, but even then, it's very likely that you can still be identified by motivated adversaries. It doesn't mean you have to give up, but, if such id is necessary for technical reasons in systemd (I guess it is), I wouldn't worry too much.
- Eddy_Viscosity2 3mo ago> motivated adversaries. This sounds like you're referring to state actors and intelligence agencies, but really this applies to the entire advertising/surveillance industry of people trying to sell you a new flavor of soda.
- CoastalCoder 3mo agoThanks, I wasn't aware of that. I have the urge to grab a pitchfork, but I know better than to make assumptions about why that functionality was added. Time to do some homework I guess.
- alimbada 3mo agoI went to check if Flatpak would protect against this but it seems although it's a wanted feature it's not so straightforward to implement: https://github.com/flatpak/flatpak/issues/4311 https://github.com/flatpak/flatpak/issues/4311
- LtWorf 3mo agofirejail has a setting to protect against it.
- ezoe 3mo agoBut does browser send these id?
- xeyownt 3mo agoNo.
- ux266478 3mo agoWow, three pieces of software I don't use for other reasons, just gained a new reason to evangelize against them!
- anthk 3mo agoAs an Hyperbola user both systemd and dbus are a no-no there.
- heresie-dabord 3mo agoThe utility of and presence of unique identifiers in software should be no surprise. But if you are using TelemetryOS (i.e. you cannot fully switch off the chatter) and your daily Web browser doesn't offer privacy extensions, you are the product.
- everdrive 3mo agoThat's good to know, thank you. I'm been considering moving away from systemd, and certainly don't use Chrome. The number of things you need to try to keep track of merely _improve_ your privacy is maddening. The whole world seems to be against you.
- LtWorf 3mo agofirejail has a setting to generate a random machine id at every run. And you should be running the browser inside firejail at all times.
- drdexebtjl 3mo agoD-Bus is much harder to get rid of than systemd. It’s best to focus your efforts into rotating these IDs.
- nostrademons 3mo agoNot using Chrome is a better bet for privacy than not using systemd or D-Bus. If you sign into Chrome (which by default happens any time you sign into a Google product), your entire browsing history is logged on Google's servers, and tied to your email address, Android ID, and any other machine identifiers Chrome can read. Anyone serious about privacy is using Firefox or Tor Browser, with various settings to harden it against tracking.
- mochapwns 3mo agoWould OpenBSD solve both of these issues or is there a device ID in there that I’m not aware of. I’ve seen that it uses a different init system and doesn’t rely on either dbus or systemd
- zbentley 3mo agoOpenBSD’s equivalent is the hw.uuid sysctl: https://man.openbsd.org/sysctl.2#HW_UUID~2 https://man.openbsd.org/sysctl.2#HW_UUID~2 Other BSDs don’t have that, but have equivalent PCI tree identifiers. “hostid”, too, is found on many systems but is much less unique as it’s often a function of local network address.
- teaearlgraycold 3mo agoTrying to imagine a world where I use Chrome unironically.
- MisterTea 3mo agoSounds like chrome is the problem.
- jcarrano 3mo agoIn dbus, it seems the feature is intended for two processes to know they can access the same shmem and other system resources. I'm struggling to understand in which circumstances would that be useful.
- salawat 3mo agoCreating an excuse for creating a machine-id to associate with network traffic. Sometimes, it is enough to have a plausible enough sounding reason to write down on paper, but you have to look at what something actually is. Any red blooded hacker knows there's what a tool is meant to be used for, and then there's what it can be used for. Less is more.