• Baŝto@discuss.tchncs.deOP
      link
      fedilink
      English
      arrow-up
      40
      arrow-down
      2
      ·
      12 hours ago

      David doesn’t want anything to do with the Linux Foundation anymore because they used AI generated art for an ad/promotion thing.

      It had a blue cup with a tux on it in it and a big tux with a 35years head, which I put on Pepper’s cup. It also had a bunch of hallucinations in it

      • rumschlumpel@feddit.org
        link
        fedilink
        arrow-up
        9
        ·
        5 hours ago

        Linux the kernel =/= Linux Foundation. The LF is a very corporate organization with millions of donation money from industry sponsors.

        • jj4211@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          7 minutes ago

          And in fact, I frequently have disagreed with the Linux foundation and think it shouldn’t carry the name Linux, as most of their projects aren’t particularly related to Linux work.

          It’s been a way for corporations to attach the Linux marketing value to their pet projects for a long time.

      • provectus@lemmy.ml
        link
        fedilink
        English
        arrow-up
        28
        arrow-down
        2
        ·
        edit-2
        11 hours ago

        I kinda agree with him as an artist. It makes me sad to see people generate art with ai when they could’ve made a noobie drawing that will still be far much better than the ai one. Ai art can be so weird as well.

        • MonkeMischief@lemmy.today
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          5 hours ago

          Case in point: The online game “Kingdom of Loathing.” I played that in like 2006 and the little martini stick dude still stands out.

  • Haley@lemmus.org
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    48
    ·
    15 hours ago

    Year of the Linux desktop when the years of neglecting security comes to bite them

      • Haley@lemmus.org
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        23
        ·
        edit-2
        14 hours ago

        MacOS, iOS, GrapheneOS (and even then, Graphene doesn’t believe themselves to be doing enough due to the fundamental limitations in AOSP)

        There is one distro trying, and even they make it clear that they’re bound by the limitations of the Linux desktop’s security model at the moment (SecureBlue).

        It is also technically possible to harden Windows to become nearly bulletproof but that usually requires third party software like ThreatLocker.

        • Holla@feddit.org
          link
          fedilink
          arrow-up
          23
          ·
          13 hours ago

          MacOS, iOS

          Do you have a source for that beyond shills and their marketing?

          There most definitively are vulnerabilities and backdoors in these OSes. Whether or not we hear of them doesn’t prove otherwise

          • Haley@lemmus.org
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            10
            ·
            13 hours ago

            My source is primarily the GrapheneOS team’s praises for how Apple handles iOS, particularly in Lockdown Mode. There was also a recent situation where they warned their users of “mercenary spyware” attacks.

            It’s also a position that many in the SecureBlue community would agree with, which is where I’ve learned the majority of my recent security stuff from.

            • Holla@feddit.org
              link
              fedilink
              arrow-up
              9
              ·
              11 hours ago

              I mean it’s commendable that Apple makes an effort to keep their users secure from third-party attackers (besides MDM software), but there’s just no telling how much control and privacy violation is going on when they’re keeping their source code secret. (“What do they have to hide? Clearly something.”)

              SecureBlue seems interesting, though most of their features look like security theater compared to the default

              • Haley@lemmus.org
                link
                fedilink
                English
                arrow-up
                2
                ·
                11 hours ago

                Suppose this is a fair point. The stuff that is exposed seems to be quite helpful, such as already integrating features like Global Privacy Control long before Google.

                As for SecureBlue… a lot of it seems quite extreme even for me but they’re doing good work overall. I was maining their browser for a bit until I realized I was fighting against the current to make it usable for my use case and I felt kind of dirty doing all that to their excellent baseline. But I did grab their sysctl config, commented out 3 or 4 that I didn’t need, and inserted it into my own. I like having more control, but I’ll gladly take a more secure option if it doesn’t affect usability significantly, so I cherrypick fixes liberally from their setup.

          • Haley@lemmus.org
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            2
            ·
            13 hours ago

            What is a turfblaster? I’m confused but maybe someone can explain that to me

            • onlinepersona@programming.dev
              link
              fedilink
              arrow-up
              2
              ·
              edit-2
              5 hours ago

              Astroturfing. Pretending to be grassroots but just being a corporate shill to be for or promote corporate services and products.

              Turfblaster is a word for someone who astroturfs.

              • Haley@lemmus.org
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                5 hours ago

                Well, it’s more so that I wished the open source community wasn’t as averse to implementing a security model that wasn’t heavily reliant on the systems being obscure. Security through obscurity is a horrid way to do such things, but it seems like that’s the way things were done before I got here.

                It would be nice to see the vision of the SecureBlue project come through elsewhere in the desktop Linux world, but any time someone so much as hints at fixing the flagrant security issues of something like the AUR, all they get is dismissal and knuckle dragging in response. I’m not a blind shill for corporate products by any means, I just would like for the community to quit treating security as an afterthought, because it’s truly needed if we want to keep the new converts safe from the looming threats that are coming day after day.

                Acknowledging the successes of projects that just so happen to not be community driven isn’t shilling inherently and I’m a little perturbed at that conclusion you immediately jumped to.

                • onlinepersona@programming.dev
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  4 hours ago

                  My bad then. I’m sorry I thought you were a shill, but those do come through here pretty often to dump their winblow and crApple dung.

                  As I said in another response, security is difficult to marry with convenience. You can see it on mobile operating systems where a flashlight app asks for network and storage permissions, and users just accept because they can’t be bothered with even reading it.

                  I too recognise that there is a lot of room to improve, but I’m hopeful that with more attention, linux will become more secure. There will be more brainpower and money flowing into it.

              • Haley@lemmus.org
                link
                fedilink
                English
                arrow-up
                4
                arrow-down
                1
                ·
                edit-2
                11 hours ago

                I mean I guess following the messaging of one of the only explicitly security-focused Linux distros is considered “astro turfing” then? Hmm.

                From their site directly:

                secureblue is for those whose first priority is using Linux, and second priority is security. secureblue does not claim to be the most secure option available on the desktop. We are limited in that regard by the current state of desktop Linux standardization, tooling, and upstream security development. What we aim for instead is to be the most secure option for those who already intend to use Linux. As such, if security is your first priority, secureblue may not be the best option for you.

                If security is your FIRST priority, they outright say their work is limited. So… that’s where I’m getting it from.

                • onlinepersona@programming.dev
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  5 hours ago

                  Linux is used in security contexts. What do you think Kali Linux is for? There’s a linux distro that is literally a hypervisor to separate everything into VMs (Qubes). Fedora allows you to activate more security options like SELinux (which is also one way Android achieves more security BTW). And I could go on, but it seems you chose to be ignorant before making the claim linux was insecure.

                  Linux distros babe many flavors and eachallows a different focus.

                • Holla@feddit.org
                  link
                  fedilink
                  arrow-up
                  6
                  ·
                  11 hours ago

                  If security is your first priority you really just gotta stop using a networked computer, and even an airgapped one would be risky