An example of how intoxicated the security world is and why you have to keep your eyes wide open to avoid being fooled.
This article was passed on to me about the state of disk encryption in Linux:
https://0pointer.net/blog/authenticated-boot-and-disk-encryption-on-linux.html
The article emphasizes the use of TPM since Linux does not use it for encryption. We all know that bitclocker has had security problems due to the use of TPM and vulnerabilities found in it that have broken its encryption. In fact no one in their right mind would trust the encryption offered by Bitclocker through the TPM, and in fact no one does, we all know it is a joke.
When we talk about cryptography there is no trust in a third party, especially if that third party is a black box like the TPM, and this is precisely what the three-letter agencies want.
When someone pursued by a three-letter agency tries to preserve the encryption of his disk, he has to rely on the encryption algorithm (opensource) and on the robustness of his key, he should not add a trusted third party, in this case a TPM.
And now back to the article, who writes this article? Lennart Poettering, who worked for Red Hat leading the development of systemd, and who joined Microsoft in 2022. The same who defends DNS servers encrypted in systemd-solved, a real attack on privacy.
In this article you can see the implications of systemd and why it is bad for Linux, clearly Microsoft and Red Hat are slowly taking over Linux and breaking the UNIX philosophy:
https://unixdigest.com/articles/the-real-motivation-behind-systemd.html
In short and as a conclusion, many researchers and developers are funded by Microsoft and the big guys, the same happens with Bitcoin, keep your eyes open.
They just want you to have no privacy and no freedom of choice.
Fucking Lennart.
I had to dig into systemd-resolved once I found it was leaking the real IP despite being connected to the VPN. 🤦🏼♂️
https://github.com/systemd/systemd/issues/6076#issuecomment-387332572 (I'm arno01 there)
Figured the best is to use a router such as GL.iNet Beryl AX (GL-MT3000) with the VPN+kill switch and then it doesn't matter how systemd or any other part of the OS is broken.
Do you know if there are alternatives with more ports?
Haven't been researching that.
Honestly, I would just use Void Linux that is systemd-free or build my own Gentoo or NixOS-based distro.
Cool. I was thinking more about whole house VPN via the router. I think I saw one before but can't remember the name of it. I'll have to have a search about.