@mcv@friendica.opensocial.space
Post #2392299
2026-03-21 09:07 UTC
@Khrys@mamot.fr
The lasting damage was knowing it could happen at all: that a single contributor with no stated organizational backing could submit compliance infrastructure for surveillance law directly into the software that boots your computer, get it merged by two Microsoft employees, and have the creator of systemd personally block the removal.
What the hell is the issue here? Do you need to be a member of an organization to submit a PR? And if the lack of organisational backing would be a problem, why is it a problem that the people merging it do work for an organisation? The only thing that matters is that an official committer approves it.
This whole article sounds like pointless fear mongering. If there's anything else to it that I'm missing, I'd love for someone to explain it.
Replies (1)
-
@draeath@infosec.exchange 2026-03-21 15:02
@mcv @Khrys@mamot.fr let's take it a bit further too. Nobody uses a pre-built systemd straight from upstream, every distribution is building and packaging it. This seems very trivial to patch right back out and/or put behind a define. (I would actually be surprised if it wasn't like that, to make compliance with different jurisdictions easier). This is literally just an additional field for dbus' consumption, right? Tempest in a teacup.