\u221e ✅

@covalent
108 Followers
25 Following
16 Posts
running a federated mastodon behind a .onion is like wearing green camo at the shopping mall
@femme @bcrypt Subgraph has a lot thicker layers on top of grsec than Qubes does on top of Xen, because grsec itself doesn't provide isolation. You have to build a sandbox yourself (in SG's case, Oz). So I don't think that grsec bugs are a proxy for SG bugs in the same way Xen bugs are a proxy for Qubes bugs.

@micahflee @bcrypt @femme @bob

Qubes has been too conservative with marketing their hardware support, I guess since they don't want to be responsible for any false positives.

But, of the processor features they use, one (VT-x) is supported almost everywhere, and the other (VT-d) is used to protect against DMA attacks (e.g., network card isolation), so if you're missing it you're no worse off than not using Qubes.

@bob @femme @bcrypt @micahflee Qubes looks like it has quite specific hardware requirements, but the hardware support is pretty broad: for instance, any i5/i7 since Sandy Bridge (6 years ago) has both VT-x for virtualization and VT-d for DMA protection, and Intel puts both features in i3's now...
@femme I mean, Qubes has existed 5x longer than Subgraph has (five years vs. one year), so you would expect to see more reported bugs, even if you assume there's equal numbers of bugs existing and equal interest in finding Xen bugs as finding Subgraph bugs...
@femme How does the comparison go when you account for the fact that Subgraph has a much shorter track record?
@bcrypt I feel like it's a mistake to have a federated service where the service shares a name with a specific instance.
@sarahjeong @isis headcanon where "account saved by the good guys, sit back and relax" means that someone squatted the name before they could get to it
@tdfischer run a yimby mastodon instance
@isis the future is an endless ring of dead accounts, each pointing to the next like a grave marker; "HERE LIES VICTORIA'S FIRST MASTODON ACCOUNT, WALK THREE NODES LEFT FOR THE NEXT" someone scrawled on a boulder, which itself once was the cornerstone of a grand shitposting empire, capable of transcending the medium itself, breaking far past the limit of a mere 140 characters and accelerating itself into our hearts