Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)C
Posts
2
Comments
634
Joined
3 yr. ago

  • I personally dont think MS did it out of maliciousness, more indifference. They wanted the security benefits, and didn't care what it cost others. But we'll likely never know what their true intent was.

    I dont know how the bazzite script does it, but any tool that can be executed from userspace that could add keys could just as easily be abused by malware to add their own signing keys, which completely defeats the purpose. Edit: see princessnorah's comments below for more details, but it is a lot more hands on, which prevents malware abusing it.

    In an ideal world, Redhat, Canonical, Suse etc could have gotten their verification keys built into every motherboard, but that still cuts out the Arch/Gentoo/flavour-of-the-month crowd. And also increases the risk that a signing key gets leaked and abused by malware.

    Its just not an easy problem to solve.

  • That should exactly fix the problem.

    The real issue is that by default, if secure boot is enabled, you won't be able to boot up into bazzite or whatever in order to run that command.

    So the user experience will be worse now, because instead of just installing and running, Linux users have to disable secure boot, boot and install their distro, run that enroll command, and then reenable secureboot. And lots of people are going to give up at step 1, and leave secureboot off.

  • This would probably gather more attention if they dropped the pointless X11 qualifier. It works on Wayland, so really, its just a cool desktop widget

  • That could be a tricky one to detect, lots of people (including OP) have accounts on different servers.

  • A simple request is sufficient, I'm only a moderator, but I'm happy to accommodate a request :)

  • Ask an admin.

  • As you've described it, and from what I have read, its very similar to how tailscale negotiates its connections.

    Does seem to be unique to Plex though.

  • I get how that could work, but what services actually do that? Homeassistant can, but that needs to be setup explicitly for it to work.

  • How does that work? Do they do something like what tailscale does to negotiate the connection? Can you point me to any doco for how that works?

  • I dont know that that is true. With cloudflare tunnels, their server.x.y.z will resolve to a cloudlfare IP address, which then tunnels it to their server? The traffic has to hit the cloudflare server, it can't short circuit that connection? Am I missing something?

  • I would assume yes, it goes out to cloudflare and back in. You want to setup an internal DNS server on your network, and resolve your servers address to its local one. That way when your outside your network, you use the tunnel, and inside it goes direct.

    1. You can't receive those emails anymore.
    2. Someone else can.
  • Yes and no. Yes, it's old and should be upgraded ideally. No in that the Linux market share is so miniscule that targeting 20.04 or other out of support linuxes isnt as favourable as targeting Windows.

    Also, the support/security update critique also applies to the community run distros as well, given they may not have the resources to keep up with security updates.

    So yeah, my risk is increasing, but I dont feel anywhere near at risk as one of the 0.43% win XP machines still floating around...

    Stats from here, no idea how accurate they are: https://gs.statcounter.com/os-version-market-share/windows/desktop/worldwide

  • Its a VM, that has a working toolchain. I am very comfortable that its safe within my environment, but in general, you're all correct, it ideally would be upgraded.

  • I3 on Ubuntu.

    Dont update unless required. Still using an 20.04 machine. As long as I can do my job, I dont need to chase the latest updates.

  • Yeah, agreed, it felt like a different show after S3. Still some good episodes in there though.

  • Thats fair, I just like the show :)

  • Misfits is a personal favourite show that explores some of those themes.

  • LLM left to its own devices.