| ▲ | jauntywundrkind a day ago | |
Imo it sounds like you've dug quite the hole for yourself. I'm sorry. I don't think it's actually as hard as you think, but given that you said you're not familiar and have pre-committed to that feeling, I think you're really not going to ever find a peace. I don't think the situation is so bad. Ripping out systemd components is not hard. They're just daemons that do what the old daemons did but more and better and cohesively. Networking would not be hard at all to replace, I could do it in a couple hours. You can easily stop Firefox from talking to your network subsystem. People don't do this because they have different priorities and philosophies than you. But what you want is right here in front of you, is a capability of this very flexible powerful networked system. Here's AppArmor:
Again I think the overall lesson for me is again that it requires attacking from above to make a better world. I have some sympathies for you with how interconnected software is. That's what radiates, and there's something really valid and good and pure about that. But I'm not the museum-piece Battlestar Galactica; I like my apps and systems talking with each other. It's great that that has gotten so much better and more secure with Wayland, but it's also flexible and powerful and capable, and I love and enjoy that so much, I treasure it.It'd be great to have people that can alloy in more conservatism, more restrictions, more care for how software interconnects. But the capability itself doesn't scare me at all, is foundational for so much, is fantastically exciting and good to me. That our ambition to do a lot and weave things together hasn't been well guarded is something I see as imminently true, but it doesn't tarnish the effort to me. It compels more, asks for more care. Just turning off the bus and walking back to manually setting up tincans and shoestring and ad-hoc per-app protocols does not fill me with any form of fulfillment or joy. I just want so much for this care not to erode & dimish, but to see & actualize some of the possibility & hope that it, under it's crusty negatively polarized shell, actually seeks. | ||
| ▲ | M95D 6 hours ago | parent [-] | |
> the capability itself doesn't scare me at all That exactly what should scare you. Until recently, the worst a malware/adware could do is corrupt your data. The solution was simple: wipe everything, restore from backup. Today, it's information leak. Leak once and there's no way to remedy the damage. "Permanent record" like Snowden said. And why it's important and should scare you: Read a bit about state security in communist countries in the '80s. I lived a bit through that. What they achieved with very limited technical capabilities is very impressive even today. A totalitarian regime today, with the tech we have now, will be permanent. Forever. No way out. No revolution possible. Considering the mass manipulation of public opinions possible today, some could even consider that inevitable. My only concern now is to not to have a preexisting "permanent record" when it happens. Capability restricted by configuration is fragile, mutable. Capability of privacy compromise should not exist at all. When the OS works against you, no configuration setting will protect you. The only thing left to do is to refuse to install anything that has dangerous capabilities, most of all, the capability to auto-update configuration or auto-install new capabilities. | ||