Looks like the "decentralized" network went down today. The main page loads but no posts or feeds load at all, and sometimes I just get a 503. Nice.
Remote
Asterisk 🇨🇦
@asterisk@social.linux.pizza
Linux enthusiast and Canadian 🇨🇦
67 Followers
84 Following
27 Posts
Joined November 05, 2022
Website:
Github:
blendOS:
Email:
me [at] asterisk [dot] lol
Open post
Replying to
@mmcblk0@mastodon.online @GrapheneOS@grapheneos.social None. Secure blue tries and uses SELinux extensively but it's nowhere close to Android (no desktop OS is)
3
2
0
0
Open post
Replying to
@maat@mastodon.social @nixCraft@mastodon.social
The Titan M2 is good hardware. A relockable bootloader is a good feature. The 2027 Motorolas will support GrapheneOS when they come out as part of the new agreement.
Edit: your arguments are just unfounded is all I'm saying, Android is much better than Linux and you have no proof to the contrary.
2
1
0
0
Open post
Replying to
@maat@mastodon.social @nixCraft@mastodon.social
Linux is a terrible option for general security, which is especially important for a device as personal as your phone. Nothing is encrypted and Flatpak's sandboxing is worse than Android 4.4 and grants broad permissions by default.
2
7
0
0
Open post
Replying to on hostux.social
@gillesmertens@hostux.social @mosquete@ursal.zone @yjeanrenaud@tech.lgbt
F-Droid stuff:
https://privsec.dev/posts/android/f-droid-security-issues/
https://xcancel.com/GrapheneOS/status/1883895255142932816
https://gitlab.com/ironfox-oss/lronFox/-/issues/7
https://github.com/obfusk/fdroid-fakesigner-poc https://github.com/CatimaLoyalty/Android/issues/2608 https://gitlab.com/fdroid/admin/-/issues/593
https://github.com/00-Evan/shattered-pixel-dungeon/issues/1394
3
1
0
0
Open post
https://asterisk.lol/blog/atproto-is-a-lie
In tech circles a lot of people have been talking about ATProto as the future of social media or building their latest flashy social network built with it, alongside companies trying to get in as well. The whole thing looked owned by one company with venture capital, but its technically decentralized layer wasn't a huge problem in and of itself. It didn't really make sense until I read Ploum's two posts about interoperability and I finally understood what the real problem was. Alongside that, I fell into a rabbit hole of other issues with Bluesky's moderation and the did:web protocol. It clearly wasn't the future, but I was so pissed at how people were talking about it as the future and "billionaire-proof social media" and how all of its problems could be solved that I wrote one big long blog post about it that I left abandoned for two years and eventually refactored and finished today. I wanted to compile all of my personal grievances with ATProto and the Silicon Valley grift culture surrounding it.
I'm really happy that there are migration services to the Fediverse as fire exits are important, but I just think a lot of people don't realize how bad ATProto really is. This goes beyond the space limits needed to host a Relay (which were fixed), or some other small comment. It's a core flaw with the protocol's design that cannot be fixed. This flaw (the interface problem) means Bluesky's control is absolute and inescapable. Any other AppView is just as centralized. Bluesky's investors did not invest into an open network, they invested into a charade, decentralization theater.
#bluesky
3
1
1
0
Open post
Replying to
@maat@mastodon.social @nixCraft@mastodon.social AppArmor and SELinux aren't really comparable to Android's ssndboxing model, which also handles app signing and certificate pinning.
Android's sandbox does not suck (bold of you to say when most Flatpaks can escape the sandbox by editing your .bashrc), Google just requires OEMs to bypass it for Play Services to obtain CTS certification (required to use the Android trademark). Alternate Android-based OSes are very secure (as long as they keep up with security patches, /e and iode do not). GrapheneOS's sandbox for it resolves this issue, letting you use it for apps that need it without security compromises.
A lot of Android's security also comes from verified boot (OS image is read-only and signed, bootloader checks the hash against the one burned in at manufacture or stored in the secure enclave at boot to ensure nothing is compromised) and a hardware secure enclave (which is not a TPM chip, its better)
edit: contact scopes (which GrapheneOS has had for ages) are coming in Android 17 to fix that issue.
1
5
0
0
Open post
Replying to
@maat@mastodon.social @nixCraft@mastodon.social They didn't suck, Google Play Services is what's always sucked (on stock play services can still access all your contacts as scopes are for third-party apps, get a Pixel or the upcoming Motorolas and flash Graphene on it if you'd like to restrict this and also regulate some other hidden permissions like Network and Sensors)
1
3
0
0
Open post
Replying to
@nixCraft@mastodon.social The funniest part is that a lot of apps use Google libraries (which means most "degoogled" setups aren't actually degoogled) which can act like a copy of Play Services themselves, so those apps could be a viable option for verification if Google insists on an app, but Google's gotta have that invasive Play Services access, right?
edit: Blog post because the article above doesn't cite its sources:
https://cloud.google.com/blog/products/identity-security/introducing-google-cloud-fraud-defense-the-next-evolution-of-recaptcha
1
1
0
0
Open post
Replying to
@rufus01@mastodon.social @nixCraft@mastodon.social Considering many haven't updated from reCAPTCHAv2 I don't think we'll see this much.
1
0
0
0
Open post
Replying to on shellsharks.social
1
0
0
0
Open post
Currently trying to track down a Steam copy of Elevator to The Moon! I managed to find the Rift version but that obviously doesn't work without Oculus components.
I think the SteamVR version might be lost media at this point. All the links are dead and there are no torrents.
I managed to find the GearVR version but that doesn't work with Oculus Touch controllers (the button it asks you to use to open the menu for a tutorial doesn't exist, softlocking the game)
https://steamdb.info/app/740400/info/
#vr #gaming
0
0
1
0
Open post
Replying to
0
0
0
0
Open post
Replying to
@collimated_thought@defcon.social @georgetakei@universeodon.com Welllllllll, you do have DNS-level adblocking so that's not entirely true. What they have access to with an app is your phone's sensors (there's no toggleable permission for this except on GrapheneOS), location, nearby devices, other apps you installed, etc.
0
0
0
0
Open post
Replying to
@mmcblk0@mastodon.online @GrapheneOS@grapheneos.social Part of what makes this work is secure enclaves and verified boot, which desktops lack (TPM is close but is barely used).
0
2
0
0
Open post
Replying to
@mmcblk0@mastodon.online @GrapheneOS@grapheneos.social No, it's perfectly fine as the host system (that's how it's meant to be used), Qubes isn't secure because there's no isolation within templates or VMs and there's no verified boot or TPM integration.
Only Android and iOS have absolute security.
0
1
0
0
Open post
Replying to on mastodon.praxis.red
@siv@mastodon.praxis.red @marti@social.martiabernathey.com @dansup@mastodon.social So having five different accounts for five different server software is more ideal because each one wants to break the spec and do its own thing?
0
0
0
0
Open post
Open post
Replying to on mastodon.social
@dansup@mastodon.social One problem, software isn't actually interoperable on Fedi or Bluesky, like how Pixelfed drops posts without images for no reason, or how people have both Pixelfed and Mastodon accounts for some reason.
https://ploum.net/2025-12-04-pixelfed-against-fediverse.html
0
2
1
0
Open post
Replying to
@thelinuxEXP@mastodon.social You could probably use Tally instead of Google Forms for these more complex polls: https://tally.so
It's not owned by Google, GDPR friendly, and block based (which allows for more customization of forms). It also comes with form logic and way more question types.
0
0
0
0
Open post
Replying to
@hidikem@piaille.fr @nixCraft@mastodon.social You need to be licensed to pass the extra checks, yellowboot OSes like Graphene pass the basic check, but yeah they obviously use the extra ones that only allow greenboot CTS certified builds.
0
0
0
0
Open post
Replying to on social.martiabernathey.com
@marti@social.martiabernathey.com @dansup@mastodon.social This comes from a social networking perspective inherited from sites like Facebook where you must have an account on every site. E-mail, for instance, does not work this way. XMPP does not work this way. If your emails were dropped by your recipient because they didn't have pictures you'd be furious.
The ideal would simply be the ability to see everything from every software, or at least from all the platforms that aren't "publish-first" (PeerTube, Micro.blog, WriteFreely, WordPress, Ghost).
0
1
0
0
Open post
Replying to
@Yama@social.n0g.de @thelinuxexperiment
I can say from experience this is false. I've been able to use Resolve on my AMD/AMD setup.
0
1
0
0
Open post
Replying to
@Yama@social.n0g.de You said AMD GPUs don't work with Resolve on Linux, I can prove they do.
0
1
1
0
Open post
Replying to
@yjeanrenaud@tech.lgbt The UI is so incredible it goes behind the status indicators on my Pixel 10 :(
0
1
0
0
Open post
Replying to on troet.cafe
@pixelschubsi@troet.cafe @gillesmertens@hostux.social The build VMs running extremely outdated versions of Debian, did they ever get around to fixing that?
0
0
0
0
Open post
Replying to
@mosquete@ursal.zone @yjeanrenaud@tech.lgbt Probably not the best idea given its security track record. Should be put on Accrescent though.
0
2
0
0


