If any of your Linux machines use SystemD, then Microsoft has done that then there’s something to be aware of with those machines. SystemD has a global system ID that can be used like the Windows GDID apparently.
Absolutely zero reason a init system needs admin date of birth. Yes separate issue entirely, but it’s showing a trend and the direction things are headed.
But that’s not at all what I asked you or what you claimed. Those are technically two different things. And not technically like yes or no. Those are entirely different security fronts.
You’ve got to back that claim up or take it back, and I have a feeling you’ll be taking it back.
It’s okay to be cautious, and it’s especially okay to warn others of trajectories that could lean into privacy or security issues, but it’s not okay to make shit up.
Lastly it’s no longer an init system. It’s a system that happens to handle init.
That’s fair. I didn’t mean MS was the threat actor, just the seed from which this grew. I definitely take that back after reading up more on where machine-id grew out of.
However, I don’t concede that machine-id is theoretical for user fingerprinting. Any software installed can read it, especially a browser. That’s the vector for tracking across the web. Do I have instances of this occurring, no. Seems plausible and the more we can sandbox things, especially “web browsers” (untrusted app runners more like it) the better.
Hey now! I can honestly say Microsoft has never done that with any of my computers!
(Why yes, they do all run Linux. How did you know?)
If any of your Linux machines use SystemD,
then Microsoft has done thatthen there’s something to be aware of with those machines. SystemD has a global system ID that can be used like the Windows GDID apparently.Edit: not MS
Source?
See discussion below. I’m making it up obviously
Tell me more. I may have to move to a distro without systemdeez.
machine-id
Okay but correlate that with the same methods and usage and by the same threat actor (MS) in this case.
Or any of the combination, as a treat
I’m not saying it’s impossible, but it’s extremely implausible.
Absolutely zero reason a init system needs admin date of birth. Yes separate issue entirely, but it’s showing a trend and the direction things are headed.
https://blog.bofh.it/debian/id_473
To be fair, yeah that shit is egregious.
But that’s not at all what I asked you or what you claimed. Those are technically two different things. And not technically like yes or no. Those are entirely different security fronts.
You’ve got to back that claim up or take it back, and I have a feeling you’ll be taking it back.
It’s okay to be cautious, and it’s especially okay to warn others of trajectories that could lean into privacy or security issues, but it’s not okay to make shit up.
Lastly it’s no longer an init system. It’s a system that happens to handle init.
That’s fair. I didn’t mean MS was the threat actor, just the seed from which this grew. I definitely take that back after reading up more on where machine-id grew out of.
However, I don’t concede that machine-id is theoretical for user fingerprinting. Any software installed can read it, especially a browser. That’s the vector for tracking across the web. Do I have instances of this occurring, no. Seems plausible and the more we can sandbox things, especially “web browsers” (untrusted app runners more like it) the better.
Probably correct. I’m not going to pretend to have the know how, but I would assume that if this was exploited widely, we’d have heard about it.
Would it be a great target? Maybe. Attack it. Show us all the love of contributing in hardening it.
To support and to need are two different verbs. Linux also needs your phone number in the user metadata by the same standard.