Experimental browser for the Atmosphere
I don't thing Apple-style binary codesigning really exists in practice. Instead I think you're supposed to use the dm-verity stuff to mount a trusted and signed OS image as your root FS, and just mount everything else as noexec (I think this can be enforced somehow).
Apr 24, 2025, 5:04 AM
{ "uri": "at://did:plc:dhpbsrfw3rxsbtqaptfdxztc/app.bsky.feed.post/3lnjwmpgbo22h", "cid": "bafyreics4ourt3pqdkpwldz5eoxvcnvj5hw4avrwcnve4bfm7hxlwchehm", "value": { "text": "I don't thing Apple-style binary codesigning really exists in practice.\n\nInstead I think you're supposed to use the dm-verity stuff to mount a trusted and signed OS image as your root FS, and just mount everything else as noexec (I think this can be enforced somehow).", "$type": "app.bsky.feed.post", "langs": [ "en" ], "reply": { "root": { "cid": "bafyreibww7vpuwhxict7x7n6tmnq7gkkdcvgaxm2kzblu2bc5cm4bfybvq", "uri": "at://did:plc:v55xjzasf6aed6u5tdbjc2jy/app.bsky.feed.post/3lnjvjntqf524", "commit": { "cid": "bafyreiddxk47qjmo3sftbwsoulzatdvjueojsjiwncoo753m2hihbci3za", "rev": "3lnjvjntz6f24" }, "validationStatus": "valid" }, "parent": { "cid": "bafyreifhxh4rqtwcixrpjjmbgc56aod77h247wgibgbzm7f3yvxht6caue", "uri": "at://did:plc:v55xjzasf6aed6u5tdbjc2jy/app.bsky.feed.post/3lnjw7o3qws2z" } }, "createdAt": "2025-04-24T05:04:00.528Z" } }