๐ Weather Latest: So hot, even the cats are melting...
this purism blog post marketing about firmware security is wild
In the case of the Librem 5 smartphone, there is no Intel ME or AMD PSP at allโoffering a truly transparent architecture.
Yet the Librem 5 has a proprietary boot ROM, additional ROM code for root of trust validation, a modem running proprietary firmware (connected via USB)
most importantly, I don't believe they actually enable secure boot, so if you're able to gain root access you could trivially replace the trustzone firmware with a modified version
To not go into any detail about the security model is pretty wild for a post titled "Hidden Operating Systems in Chips vs. Secure, Auditable OSes: A Cybersecurity Comparison"...
Operators are cheering at the Mastodon Genuine Advantage HQ as the new mastodon.social TOS appears to require the use of Genuine Mastodon Software! A victory worth celebrating, as you should always use Genuine Mastodon Software.
@domi DNS root is from now on managed by Oracle Corporation
#pkgconf 2.5.0 is released, with a few new interesting features.
the big one is preloaded packages, which is discussed here: https://social.treehouse.systems/@ariadne/114626642134151151
pkgconf also grew unveil(2) and pledge(2) support on systems that implement these hardening features.
we also cleaned up a lot of minor memory safety issues identified by the GCC 15 static analyzer.
oh, and importantly, this is the first release where the release tarballs are generated and published by CI.
No more embargoed security issues for libxml2: https://gitlab.gnome.org/GNOME/libxml2/-/issues/913
Yeah I'll have the uh.. EFI Shell with a diet coke