• 1 Post
  • 234 Comments
Joined 3 years ago
cake
Cake day: July 31st, 2023

help-circle


  • “But that’s unenforceable”, some will claim.

    And to that, let me remind us all of a little-known concept called cryptographic attestation. If that doesn’t ring any bells, then the term “secure boot” should.

    Once this shit passes into law, that’s the next step. Operating system vendors have their private keys to sign attestation tokens saying “John Johnson is an adult” and you’re only getting one if you verify your government ID. When you go to a website, your browser sends your signed token to the website and then the website checks if it’s a valid token signed by Microsoft, Apple, or Google.

    But Linux?, you may be wondering. No. No Linux. Kiss it good-bye. Your bank will “require” identity attestation for “extra security”, and your bank doesn’t give a fuck about Linux. Your bank will check against whatever list of public keys they want to trust, and it ain’t going to include anything not backed by a global megacorporation.




  • It’s not. They both expose a POSIX API and userspace, but the underlying architecture is very different. macOS is in part based on the Mach microkernel, and creating a process has a bunch of work related to that.

    Even ignoring that difference, macOS has built-in signature checking that suspends a newly-started process the first time its executable is seen.











  • I have tried it multiple times over the years and I did not have great luck with things “just working” as everyone claims.

    This is why I don’t like recommending LTS distros for anything other than servers. The Linux kernel and desktop software moves fast these days, and running 2 year old kernel and DE means missing out on the fixes and improvements that the “it just works” people are talking about.



  • Legal, probably. Whichever corporations push that hypothetical bill are going to write it very specifically to ensure that it excludes their use cases.

    Here’s an example of how they could do it:

    S.A.V.E.K.I.D.S:
    Support Age Verification Environments Keeping Internet Detectable Signals

    Blah blah pretext and background information…

    Blah blah surface-level purported reason for the bill is to prevent kids from bypassing age verification checks by using a VPN to pretend they’re a resident of another country…

    No entity operating in or doing business within <jurisdiction> may provide services or make available technology that irreversibly redirects, masks, or otherwise obscures internet-destined traffic to appear as originating from any source other than the internet-connected network in which it was generated.

    Site–to-site VPN? Fine, it’s destined for the intranet.
    NAT? Also fine, it is the originating internet-connected network.
    HTTP reverse proxies? Still fine, they pass the origin IP along.

    VPN that routes all traffic through it? You’re getting locked up and they’re throwing away the key.



  • There’s a few of them. Notably, the guy who didn’t care that AI art is built on the back of copyright violations getting pissy about his AI-generated art not being eligible for copyright.

    But more importantly here, I don’t think most artists in the gaming industry are in much of a position where they can stand by their artistic integrity. If every publisher pushes studios into using AI to be more “productive”, the choice becomes between slopping or starving—and most people don’t like starving.

    We as consumers are the only ones that can afford to push back against this shit. Our survival doesn’t rely on buying DLSS 5 games so we have the ability to boycott them to send a message.