That’s fair. I didn’t mean MS was the threat actor, just the seed from which this grew. I definitely take that back after reading up more on where machine-id grew out of.
However, I don’t concede that machine-id is theoretical for user fingerprinting. Any software installed can read it, especially a browser. That’s the vector for tracking across the web. Do I have instances of this occurring, no. Seems plausible and the more we can sandbox things, especially “web browsers” (untrusted app runners more like it) the better.
I’m not technically inclined enough to harden against that, nor do ai really have the inclination. But here is a thread on that topic where I even heard about it.
I did just read I think 90% of that, and it just seems like that person is sour about systemd in general.
I agree it’s not unix/Linux philosophy but it’s the best we have.
Does it do too much? Maybe. I haven’t seen that exploited on a large scale in the real world, but it’s definitely a golden key.
There are options. But it’s just one of those things. You’re pissing in the wind unless you’re willing to write it yourself. You can use non systemd distros or even use bsd.
All that said, you’re absolutely right to be concerned, but speaking on it like it’s an active vulnerability is dangerous.
It’s also evident that it’s reliant on the software you run, it’s not systemd that’s giving you away, it’s your application that you chose to install that’s abusing or neglegent of systemd’s access.
That’s fair. I didn’t mean MS was the threat actor, just the seed from which this grew. I definitely take that back after reading up more on where machine-id grew out of.
However, I don’t concede that machine-id is theoretical for user fingerprinting. Any software installed can read it, especially a browser. That’s the vector for tracking across the web. Do I have instances of this occurring, no. Seems plausible and the more we can sandbox things, especially “web browsers” (untrusted app runners more like it) the better.
Probably correct. I’m not going to pretend to have the know how, but I would assume that if this was exploited widely, we’d have heard about it.
Would it be a great target? Maybe. Attack it. Show us all the love of contributing in hardening it.
I’m not technically inclined enough to harden against that, nor do ai really have the inclination. But here is a thread on that topic where I even heard about it.
!privacy@lemmy.ml
https://lemmy.ml/post/49710604
I did just read I think 90% of that, and it just seems like that person is sour about systemd in general.
I agree it’s not unix/Linux philosophy but it’s the best we have.
Does it do too much? Maybe. I haven’t seen that exploited on a large scale in the real world, but it’s definitely a golden key.
There are options. But it’s just one of those things. You’re pissing in the wind unless you’re willing to write it yourself. You can use non systemd distros or even use bsd.
All that said, you’re absolutely right to be concerned, but speaking on it like it’s an active vulnerability is dangerous.
It’s also evident that it’s reliant on the software you run, it’s not systemd that’s giving you away, it’s your application that you chose to install that’s abusing or neglegent of systemd’s access.