I use heads firmware, which seals an otp key in the tpm to let you verify the integrity of the firmware, which then uses your gpg pubkey written into the firmware to verify the integrity of the boot partition.
An open, self-controlled equivalent to secure boot that relies on the tpm and your own gpg key, instead of on vendor secure boot signing keys. Very cool project!
- 0 Posts
- 23 Comments
mlfh@lemmy.sdf.orgto Green Energy@slrpnk.net•Finland warms up the world’s largest sand battery, and the economics look appealing9·27 days ago100MWh from that one little silo, that’s incredible.
I tried to buy a drink on a united flight once, and the poor guy had to tell me the only way I could pay for it was to download the united airlines app via the in-flight wifi and enter my card details there. Which I couldn’t do, so fuck me I guess.
mlfh@lemmy.sdf.orgto Ask Lemmy@lemmy.world•Why are Jews so unpleasant as people individually5·1 month agoFuck outta here with this bullshit.
mlfh@lemmy.sdf.orgto Ask Lemmy@lemmy.world•What is some pleasantly menacing music, preferably longer form?4·1 month agoThrenody to the Victims of Hiroshima - Krzysztof Penderecki
10 minutes of eerie, menacing beauty.
I use Vanadium/Trivalent (GrapheneOS fork of mobile Chromium and its desktop equivalent) for general internet use on a general-use system, and Firefox inside of specific qubes for specific purposes otherwise.
On a general-use system, the additional security of Vanadium and Trivalent give me a bit of peace of mind when using the same browser for admin work, sensitive stuff like banking, and general browsing.
With the Qubes model, everything is segmented and isolated anyway, so I can use Firefox, which despite its flaws has been my favorite since the Netscape days.
mlfh@lemmy.sdf.orgto Ask Lemmy@lemmy.world•how do I know that you guys are real and not bots?2·2 months agoThe dystopian part is being required by law to use a specific form of authentication tied to your real identity by the government in order to access the internet.
mlfh@lemmy.sdf.orgto Ask Lemmy@lemmy.world•how do I know that you guys are real and not bots?6·2 months agoThat sounds like a horribly dystopian solution to a horribly dystopian problem.
mlfh@lemmy.sdf.orgto Asklemmy@lemmy.ml•What are some fictional side characters that have deeply resonated with you?6·2 months agoFour Weddings and a Funeral is a movie I adore entirely for the side characters, and pretty much ignore the two main characters and storyline completely.
The main friend group feels so real and alive and lovely, they’re charming and funny, and watching them be friends at their weddings and funeral feels like optimistic slice-of-life escapism. And beyond that, pretty much every other side character is memorable and funny and a joy to watch, especially Rowan Atkinson as the anxious priest. Great movie, 10/10, can’t remember the main characters at all.
Yep exactly! Setting up a raspberry pi low-performance computing cluster with secondary usb nics, going slowly insane trying to figure out why the vlan interfaces wouldn’t work when their base interfaces worked just fine, and going down all of the wrong rabbit holes along the way.
ifupdown2 has a 15-character interface name limit, and the systemd predictable interface naming system uses the mac address for usb nics (giving them a 15-character name), so if you try to create a vlan subinterface of a usb nic using the standard interface.vlan naming scheme on a systemd host, it will fail, and you’ll have to set up systemd network link files to rename the base interfaces to something shorter.
mlfh@lemmy.sdf.orgto Ask Lemmy@lemmy.world•How long is a meter? (Only weird answers/definitions allowed)10·2 months agoYes, with the official M16A4 unit being defined as 1/100th the length between the goal lines of an American Football field.
mlfh@lemmy.sdf.orgto Linux@lemmy.ml•Linux: How to use energy better in general by fine-tuning laptop battery?3·2 months agoThe ups has data output to my firewall/router via usb, which the baremetal servers all connect to via apcupsd. When the ups loses or regains AC power, it broadcasts a message to all of them and they’re each scripted to act accordingly: laptops run on their own batteries, vms migrate over to laptops, non-vital hardware shuts down, etc.
mlfh@lemmy.sdf.orgto Linux@lemmy.ml•Linux: How to use energy better in general by fine-tuning laptop battery?14·2 months agoSome laptop battery firmware allows you to force discharge even when connected to AC, and if your laptop can use the
tlp recalibrate
ortlp discharge
commands then yours is supported.I use this to power my thinkpad servers off of their own batteries during a power outage, to reduce load on my UPS. Great feature.
mlfh@lemmy.sdf.orgtoUnited States | News & Politics@midwest.social•Former Bush Housing Official Claims Government Has Spent $21 Trillion Building an Underground Doomsday ‘Base’34·2 months agoTL;DR: someone goes on Tucker Carlson’s podcast and claims that nearly the entire GDP of the US (Trillion with a T was not a typo) was spent building secret underground cities.
mlfh@lemmy.sdf.orgto Ask Lemmy@lemmy.world•Is there any lemmy server hosted from the USA ?8·3 months agoYou can! I registered my first account on ml, and moved to sdf, with a third on world as a backup. You can open one on every instance if you want, or more as individual instance rules permit.
mlfh@lemmy.sdf.orgto Linux@lemmy.ml•Atomic Linux Distros: What Barriers Stand Between You and Making the Switch?4·3 months agoI switched a workstation to Secureblue for the very specific security priorities targeted by that project, but I think for the majority of users, the main reason for not switching to atomic is one you mentioned: why fix what isn’t broken? The main selling point promoted to potential new users seems to be that updates don’t break anything, but I can’t remember a single time since Debian Sarge that an update broke anything for me, and I actually find the rpm-ostree package layering and updating process to be far more of a headache than otherwise.
Unless it’s prepackaged like a steam deck, moving from the traditional way of doing things to atomic is a major change. Like any major change, people need a good reason to make it, and I think right now the only compelling ones are either hyper-specific (switching to okd and needing to build it on coreos, wanting to move to a specific atomic project, etc.), or just general curiosity.
Band of Brothers. The intro is so long, but feels like an important part of the whole experience.
mlfh@lemmy.sdf.orgto Selfhosted@lemmy.world•Why is my server using all my Swap but I have RAM to spare?English10·3 months agoThat’s why you can adjust swappiness, or designate a different high-endurance storage device for it.
Edgelord atheist mad at christianity and islam: “every religion is genocide and hate, and I hate them.”
Buddhists , jains, pagans, etc: “hey excuse you buddy.”