Show more

Enough time has passed that I feel like I can share my (possibly controversial) perspective on software supply chain security without it seeming reactive or opportunistic: puri.sm/posts/the-future-of-so

Have you ever noticed how many security experts speak out against encryption backdoors, but design systems that anchor all trust in their company's signing key?

Michigan police solved a murder with recordings of the suspect's voice stored on the victim's truck infotainment system. Michigan police pull data from cars "sometimes two to three times a week." nbcnews.com/tech/tech-news/sni

Imagine if your ISP kicked your laptop off the Internet because Microsoft stopped providing it security updates. Imagine having to buy a new laptop every 2-3 years just so you could get updates. Phones are just small computers, they shouldn't have special rules.

Show thread

TMobile is kicking old Android phones off their network in January because vendors have abandoned the hardware and they no longer get security updates. Android's model of forcing you to buy new hardware every few years to get security updates is broken. tmonews.com/2020/12/t-mobile-w

I don't want a lot for Christmas
There is just one thing I need
I would like to download software
With a license that is freed

I just want code for my own
More than you could ever know
Make my wish come true
All I want for Christmas is GNU

Hot off the presses! @doc and @katherined talk to @kyle and Petros Koutoupis about the SolarWinds hack, and Facebook's reaction to Apple privacy initiatives.
reality2cast.com/53

#solarwinds #privacy #technology #podcast #newepisode

I have opinions on the current supply chain attacks and software supply chain security but given my employer, I feel like sharing them now would seem like ambulance chasing so I'm waiting until the dust settles.

I also would never have guessed that SkyNet would be powered by Kubernetes...

Show thread

Here's a fun pull quote: "The AI system was deliberately designed without a manual override to "provoke thought and learning in the test environment""

Show thread

My big fat Greek reading list. (Actually almost finished with Durant, and this will be my second time reading The Iliad, but first time with Fagles translation.)

Want to take a COVID test at home? You must install an app to get the results: "Ellume’s test requires users to download an app on their smartphone to learn their test result. That app automatically sends data by Zip code to the cloud"

washingtonpost.com/health/2020

It's also because tight control w/ trust rooted in the vendor is "easy mode" for lazy security engineers. It's much harder to design security measures that treat end users like adults.

Show thread

It's because most vendors think of customers as children that must be protected from themselves by removing as much agency and control as possible. This also makes customers completely dependent on them.

Show thread

Have you noticed that a parent's default way to protect a child's security w/ tech (lock the device, tightly restrict what they can do, spy on everything) is exactly the same approach most vendors use to protect an adult customer's security?

With latest updates, GNOME Web (Epiphany) can play YouTube videos on the Librem 5, so you won't have to switch to Firefox to do that anymore. And you won't believe where the bug was located[1]! ;) Call `sudo apt install gstreamer1.0-libav` or wait a few days until it's installed by default with the next update and enjoy. @purism

[1] it was in glibc...

Apple always uses security and privacy as a cover for more control: "Apple says it must tightly control the way software is installed ... to protect its customers from ... viruses and other security threats and ... apps that invade its customers’ privacy." washingtonpost.com/technology/

When it's particularly cold in my office, either my desk or my Model M keyboard contract unevenly such that the keyboard is no longer flat on the desk and wobbles until the office warms up.

Show more
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml