I believe that’s on purpose so people can easily accept it and they can do worse later.
That point, I disagree on, because systemd (not) implementing this doesn’t actually make it easier (or harder). Distros that want to comply would just write a file for it somewhere instead. Distros that don’t comply will just not implement any verification process.
What systemd does here is offer a solution to secure it centrally (see the commit discussion about the most efficient and reasonable way to wipe that info from memory again). Considering the whole issue, I think its impact on feasibility of verification is minor, while the advantages of standardisation make it preferable to a wild growth of uncontrolled alternatives.
Corporations are behind this, don’t forget that.
Another user pointed out the concept of anticipatory obedience to me, and in that context, corporations pre-emptively bowing to authoritarian surveillance is definitely a cowardly move. We agree on that.
Here’s to hoping this entire discussion becomes just as pointless as you expect the PR to become. If that’s what I end up being wrong about, I’ll gladly take the L for cynicism and the W for privacy.
0
0
2