Ultimately, the problem is much bigger than /etc/machine-id since there are dozens of hardware IDs on any PC that can be used by malicious telemetry to silently to uniquely identify and track you, and the only solution to this problem currently is to make sure you really trust any software you use.
Systemd, in particular, acts a lot like malware for Linux because if you try to reset your machine-id a long list of stuff that breaks in in it. You could make a cron script to reset /etc/machine-id every day, but machine-id is so deep in the stack that you’d also have to reboot to ensure it’s updated.
The bigger concern here is that the app isn’t sandboxed, not machine id. Run something like secureblue that has better sandboxing by default
Wat? If you have something running on your system that’s tracking you, you are already fucked. It doesn’t require that file. It can just create one anywhere on the system and use it, if need be.
The problem with machine-id specifically is that it’s become a standard way for the browser to identify itself. There obviously other ways you can be tracked, but this is a very low bar and a common way of sites tracking people.
Firejail
The Impermanence module for NixOS recommends persisting
/etc/machine-id. Is there any downside to not persisting it? (which is currently what I’m doing because I get errors when I do)for most desktop users, not persisting /etc/machine-id is usually fine, but there are some specific scenarios where it can cause issues. Systemd uses machine-id to tag log entries. If it changes, you might lose the ability to correlate logs across boot sessions in journalctl. This is mostly an annoyance for debugging rather than a functional problem. A few NixOS modules like services.openssh or certain mail servers use machine-id for generating default host keys or identifiers. Changing it might cause warnings on first boot after a change, but usually nothing breaks since they fall back to other identifiers.
I was unaware of this. As far as I can understand this is a design for admins who manage fleets and virtual machines, so it’s not surprising it comes from Lennart and systemd. However, even openbsd has /etc/machine-id. Over in bsd land it seems to come from dbus. Is the file a systemd design or a dbus design? Is it something users should be concerned about… probably, but all of computing is a nightmare. Just another fire to add to the fire pit.
Yeah, since OpenBSD doesn’t use systemd, that points to dbus origins for the file.
so, for the noobs, what do we do? do we just live with thay file untouched there? :S
Pretty much…
So then as long as my machine doesn’t have systemd im fine?
not necessarily, but it’s definitely easier to avoid having machine id without it
You ever tried Kodachi Linux?
as I recall it does actively randomize machine-id?







