▲ 190 ▼ Fedora threatened with legal action from OBS Studio due to their Flatpak packaging (www.gamingonlinux.com) submitted 2 years ago by cm0002@lemmy.world to c/linux@programming.dev 38 comments fedilink hide all child comments
[–] ArsonButCute@lemmy.dbzer0.com 15 points 2 years ago (13 children) Source? permalink fedilink source parent hideshow 13 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (12 children) It doesn't have package signing. The source is their documentation. permalink fedilink source parent hideshow 12 child comments replies: [–] MissingInteger@lemm.ee 10 points 2 years ago (11 children) flatpak build-sign, is what I can find in the documentation. permalink fedilink source parent hideshow 11 child comments replies: [+] jagged_circle@feddit.nl -9 points 2 years ago* (10 children) Yeah, thats optional. Unlike actual secure package managers like apt, where signing has been required since 2005. What you need to look at is the docs for installing, and note it doesn't say anything about requiring valid signatures after downloading a payload. Flatpak doesn't care about security. avoid them. permalink fedilink source parent hideshow 10 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago* (last edited 2 years ago) (9 children) This seems to be blatant misinformation. The default seems to require a gpg signature. It can be disabled for a remote with --no-gpg-verify, but the default for installing and building definitely requires a signature. You keep talking about the docs, so please show me where is says that in the Flatpak Documentation. permalink fedilink source parent hideshow 9 child comments replies: [+] jagged_circle@feddit.nl -12 points 2 years ago (8 children) You're the one spreading misinformation. The burden of proof is on you. I linked you to the docs showing how package signatures have been required in apt since 2005. Most package managers do not have signature verification. Point me to where the docs say signatures are required to be verified after download. permalink fedilink source parent hideshow 8 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago (5 children) You have not provided a single link. I'm am no expert on flatpak and just did some basic searching. From reading the command reference it seems GPG-Verification is enabled for each remote and can't be disabled/enabled for each install. I can just find some issues where gpg verification fails Error: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) error: Failed to install bundle fr.handbrake.ghb: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) Documentation seems to be more user oriented and not developer oriented maybe someone more knowledgeble can go in the source code and tell us how it actually works. permalink fedilink source parent hideshow 5 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent [–] ms5K8oWx@programming.dev 8 points 2 years ago* (1 child) The burden of proof is on you. You accused flatpak of being insecure. The burden to prove that is totally on you. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent
[–] jagged_circle@feddit.nl 0 points 2 years ago (12 children) It doesn't have package signing. The source is their documentation. permalink fedilink source parent hideshow 12 child comments replies: [–] MissingInteger@lemm.ee 10 points 2 years ago (11 children) flatpak build-sign, is what I can find in the documentation. permalink fedilink source parent hideshow 11 child comments replies: [+] jagged_circle@feddit.nl -9 points 2 years ago* (10 children) Yeah, thats optional. Unlike actual secure package managers like apt, where signing has been required since 2005. What you need to look at is the docs for installing, and note it doesn't say anything about requiring valid signatures after downloading a payload. Flatpak doesn't care about security. avoid them. permalink fedilink source parent hideshow 10 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago* (last edited 2 years ago) (9 children) This seems to be blatant misinformation. The default seems to require a gpg signature. It can be disabled for a remote with --no-gpg-verify, but the default for installing and building definitely requires a signature. You keep talking about the docs, so please show me where is says that in the Flatpak Documentation. permalink fedilink source parent hideshow 9 child comments replies: [+] jagged_circle@feddit.nl -12 points 2 years ago (8 children) You're the one spreading misinformation. The burden of proof is on you. I linked you to the docs showing how package signatures have been required in apt since 2005. Most package managers do not have signature verification. Point me to where the docs say signatures are required to be verified after download. permalink fedilink source parent hideshow 8 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago (5 children) You have not provided a single link. I'm am no expert on flatpak and just did some basic searching. From reading the command reference it seems GPG-Verification is enabled for each remote and can't be disabled/enabled for each install. I can just find some issues where gpg verification fails Error: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) error: Failed to install bundle fr.handbrake.ghb: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) Documentation seems to be more user oriented and not developer oriented maybe someone more knowledgeble can go in the source code and tell us how it actually works. permalink fedilink source parent hideshow 5 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent [–] ms5K8oWx@programming.dev 8 points 2 years ago* (1 child) The burden of proof is on you. You accused flatpak of being insecure. The burden to prove that is totally on you. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent
[–] MissingInteger@lemm.ee 10 points 2 years ago (11 children) flatpak build-sign, is what I can find in the documentation. permalink fedilink source parent hideshow 11 child comments replies: [+] jagged_circle@feddit.nl -9 points 2 years ago* (10 children) Yeah, thats optional. Unlike actual secure package managers like apt, where signing has been required since 2005. What you need to look at is the docs for installing, and note it doesn't say anything about requiring valid signatures after downloading a payload. Flatpak doesn't care about security. avoid them. permalink fedilink source parent hideshow 10 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago* (last edited 2 years ago) (9 children) This seems to be blatant misinformation. The default seems to require a gpg signature. It can be disabled for a remote with --no-gpg-verify, but the default for installing and building definitely requires a signature. You keep talking about the docs, so please show me where is says that in the Flatpak Documentation. permalink fedilink source parent hideshow 9 child comments replies: [+] jagged_circle@feddit.nl -12 points 2 years ago (8 children) You're the one spreading misinformation. The burden of proof is on you. I linked you to the docs showing how package signatures have been required in apt since 2005. Most package managers do not have signature verification. Point me to where the docs say signatures are required to be verified after download. permalink fedilink source parent hideshow 8 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago (5 children) You have not provided a single link. I'm am no expert on flatpak and just did some basic searching. From reading the command reference it seems GPG-Verification is enabled for each remote and can't be disabled/enabled for each install. I can just find some issues where gpg verification fails Error: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) error: Failed to install bundle fr.handbrake.ghb: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) Documentation seems to be more user oriented and not developer oriented maybe someone more knowledgeble can go in the source code and tell us how it actually works. permalink fedilink source parent hideshow 5 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent [–] ms5K8oWx@programming.dev 8 points 2 years ago* (1 child) The burden of proof is on you. You accused flatpak of being insecure. The burden to prove that is totally on you. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent
[+] jagged_circle@feddit.nl -9 points 2 years ago* (10 children) Yeah, thats optional. Unlike actual secure package managers like apt, where signing has been required since 2005. What you need to look at is the docs for installing, and note it doesn't say anything about requiring valid signatures after downloading a payload. Flatpak doesn't care about security. avoid them. permalink fedilink source parent hideshow 10 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago* (last edited 2 years ago) (9 children) This seems to be blatant misinformation. The default seems to require a gpg signature. It can be disabled for a remote with --no-gpg-verify, but the default for installing and building definitely requires a signature. You keep talking about the docs, so please show me where is says that in the Flatpak Documentation. permalink fedilink source parent hideshow 9 child comments replies: [+] jagged_circle@feddit.nl -12 points 2 years ago (8 children) You're the one spreading misinformation. The burden of proof is on you. I linked you to the docs showing how package signatures have been required in apt since 2005. Most package managers do not have signature verification. Point me to where the docs say signatures are required to be verified after download. permalink fedilink source parent hideshow 8 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago (5 children) You have not provided a single link. I'm am no expert on flatpak and just did some basic searching. From reading the command reference it seems GPG-Verification is enabled for each remote and can't be disabled/enabled for each install. I can just find some issues where gpg verification fails Error: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) error: Failed to install bundle fr.handbrake.ghb: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) Documentation seems to be more user oriented and not developer oriented maybe someone more knowledgeble can go in the source code and tell us how it actually works. permalink fedilink source parent hideshow 5 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent [–] ms5K8oWx@programming.dev 8 points 2 years ago* (1 child) The burden of proof is on you. You accused flatpak of being insecure. The burden to prove that is totally on you. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent
[–] MissingInteger@lemm.ee 8 points 2 years ago* (last edited 2 years ago) (9 children) This seems to be blatant misinformation. The default seems to require a gpg signature. It can be disabled for a remote with --no-gpg-verify, but the default for installing and building definitely requires a signature. You keep talking about the docs, so please show me where is says that in the Flatpak Documentation. permalink fedilink source parent hideshow 9 child comments replies: [+] jagged_circle@feddit.nl -12 points 2 years ago (8 children) You're the one spreading misinformation. The burden of proof is on you. I linked you to the docs showing how package signatures have been required in apt since 2005. Most package managers do not have signature verification. Point me to where the docs say signatures are required to be verified after download. permalink fedilink source parent hideshow 8 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago (5 children) You have not provided a single link. I'm am no expert on flatpak and just did some basic searching. From reading the command reference it seems GPG-Verification is enabled for each remote and can't be disabled/enabled for each install. I can just find some issues where gpg verification fails Error: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) error: Failed to install bundle fr.handbrake.ghb: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) Documentation seems to be more user oriented and not developer oriented maybe someone more knowledgeble can go in the source code and tell us how it actually works. permalink fedilink source parent hideshow 5 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent [–] ms5K8oWx@programming.dev 8 points 2 years ago* (1 child) The burden of proof is on you. You accused flatpak of being insecure. The burden to prove that is totally on you. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent
[+] jagged_circle@feddit.nl -12 points 2 years ago (8 children) You're the one spreading misinformation. The burden of proof is on you. I linked you to the docs showing how package signatures have been required in apt since 2005. Most package managers do not have signature verification. Point me to where the docs say signatures are required to be verified after download. permalink fedilink source parent hideshow 8 child comments replies: [–] MissingInteger@lemm.ee 8 points 2 years ago (5 children) You have not provided a single link. I'm am no expert on flatpak and just did some basic searching. From reading the command reference it seems GPG-Verification is enabled for each remote and can't be disabled/enabled for each install. I can just find some issues where gpg verification fails Error: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) error: Failed to install bundle fr.handbrake.ghb: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) Documentation seems to be more user oriented and not developer oriented maybe someone more knowledgeble can go in the source code and tell us how it actually works. permalink fedilink source parent hideshow 5 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent [–] ms5K8oWx@programming.dev 8 points 2 years ago* (1 child) The burden of proof is on you. You accused flatpak of being insecure. The burden to prove that is totally on you. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent
[–] MissingInteger@lemm.ee 8 points 2 years ago (5 children) You have not provided a single link. I'm am no expert on flatpak and just did some basic searching. From reading the command reference it seems GPG-Verification is enabled for each remote and can't be disabled/enabled for each install. I can just find some issues where gpg verification fails Error: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) error: Failed to install bundle fr.handbrake.ghb: GPG verification enabled, but no signatures found (use gpg-verify=false in remote config to disable) Documentation seems to be more user oriented and not developer oriented maybe someone more knowledgeble can go in the source code and tell us how it actually works. permalink fedilink source parent hideshow 5 child comments replies: [–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent
[–] jagged_circle@feddit.nl 0 points 2 years ago (4 children) Sorry here's the link https://wiki.debian.org/SecureApt permalink fedilink source parent hideshow 4 child comments replies: [–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent
[–] MissingInteger@lemm.ee 6 points 2 years ago (3 children) So you linked to apt. I guess good for anyone who finds this interesting… But more on topic here is is a link to answer from 2020 from an flatpak maintainer: If a user installs or updates a specific app-id the code verifies that: The new app is gpg signed by a trusted key Checksum verifying that all files are untampered with The new app has that app id The new app has a later timestamp on update permalink fedilink source parent hideshow 3 child comments replies: [–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent
[–] jagged_circle@feddit.nl -2 points 2 years ago (2 children) Link me to the docs that say this permalink fedilink source parent hideshow 2 child comments replies: [–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent
[–] MissingInteger@lemm.ee 5 points 2 years ago (1 child) You are not arguing in good faith. I have linked multiple times to the docs and to the GitHub repository of flatpak. Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent
[–] jagged_circle@feddit.nl -2 points 2 years ago You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads. This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts. permalink fedilink source parent
[–] ms5K8oWx@programming.dev 8 points 2 years ago* (1 child) The burden of proof is on you. You accused flatpak of being insecure. The burden to prove that is totally on you. permalink fedilink source parent hideshow 1 child comment replies: [–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent
[–] jagged_circle@feddit.nl -4 points 2 years ago Nah, tech is insecure by default. permalink fedilink source parent