Remix.run Logo
fransje26 3 days ago

https://ejona.ersoft.org/archive/2024/03/03/flatpak-perm-sur...

akimbostrawman 2 days ago | parent | next [-]

Flatpaks can have insecure permissions which are not only transparent but easily editable. Meanwhile native packages are guaranteed to have insecure/all permissions.

Joel_Mckay 2 days ago | parent [-]

In general, SELinux profiles use Mandatory Access Control, and not Discretionary Access Control. However, most desktop users find it difficult to understand, and often have bigger problems from reading silly posts off the web.

An outdated old package library relies on people understanding/tracking the complete OS scope of dependencies, and that is infeasible for a small team.

If someone wants in... they will get in eventually... but faster on a NERF'd Arch install. =3

akimbostrawman 2 days ago | parent [-]

>most desktop users find it difficult to understand, and often have bigger problems

That is exactly the strong point of flatpaks. It's a lot easier to use toggle in a GUI for permissions than write whole new profiles. Not to mention that many even disable selinux because it is difficult.

>An outdated old package library relies on people understanding/tracking the complete OS

It takes 0 understanding to copy paste a outdated package warning and report that to the repo listed in flathub. It explicitly tells you as much.

Joel_Mckay 3 days ago | parent | prev [-]

It seems the AstroTurf'ing folks buried the parent as children often do.

But thanks for trying to post actual relevant data on the topic. =3

"Popcorn Music Video" (The Muppets)

https://www.youtube.com/watch?v=Gwg5ey6236o