myersguy

joined 2 years ago
[–] myersguy@lemmy.simpl.website 2 points 3 months ago (1 children)

Your comment also contained

The filesystem itself is also read-only.

Which is what led to the further discussion of root making that not so.

I don't believe that to be the intent of the OP's comment, given their second sentence, but they are welcome to state otherwise. I just don't want them thinking that an immutable distribution gives them some kind of bulletproof security that it doesn't.

[–] myersguy@lemmy.simpl.website 1 points 3 months ago* (last edited 3 months ago) (3 children)

While you are correct, any system is compromised if you have root, so isn’t that irrelevant at that point?

The original context for the comment chain was:

Because even if an attacker could gain access even as root he cannot modify system files.

So no, it's completely relevant.

[–] myersguy@lemmy.simpl.website 2 points 3 months ago (7 children)

Someone with root can run ostree admin unlock --hotfix to make /usr writable. Someone with root can also delete all restore points.

It would be strange for them to call it that if it actually means “completely irrelevant from a security perspective”.

See the comment by superkret.

[–] myersguy@lemmy.simpl.website 5 points 3 months ago* (last edited 3 months ago) (11 children)

An attacker escaping from a container can’t be system root as Podman runs rootless (without some other exploit or weak password).

That would be true of podman running anywhere, and is not unique to an immutable distribution.

The filesystem itself is also read-only.

You can change that real quick if you have root access.

[–] myersguy@lemmy.simpl.website 9 points 3 months ago (14 children)

Because even if an attacker could gain access even as root he cannot modify system files.

They 100% can.

[–] myersguy@lemmy.simpl.website 12 points 3 months ago

I really appreciate Open Source Alternative To for this (although their theme seems a little broken atm).

[–] myersguy@lemmy.simpl.website 6 points 3 months ago (1 children)

The "down" was definitely edited after the fact.

[–] myersguy@lemmy.simpl.website 19 points 3 months ago (2 children)

Thanks! Not quite as wild as I was expecting (kind of surprised this was enough to push them to delete their account)

[–] myersguy@lemmy.simpl.website 18 points 3 months ago (60 children)

Do you have any sources for this?

[–] myersguy@lemmy.simpl.website 12 points 3 months ago* (last edited 3 months ago) (3 children)

The GitHub says they plan on adding other fediverse connections in the future.

[–] myersguy@lemmy.simpl.website 6 points 4 months ago* (last edited 4 months ago) (1 children)

What is PortProton doing that could increase performance? At the end of the day, won't this tool just set up a wineprefix for your game and then launch it using wine/proton, just like other tools of this nature?

[–] myersguy@lemmy.simpl.website 4 points 4 months ago* (last edited 4 months ago) (1 children)

Where can you find an N100 for $60 with 4GB of memory?

EDIT: Nvm, found the comment replying to this mentioning Radxa boards. Just found them the other day. Very interested.

view more: ‹ prev next ›