190
you are viewing a single comment's thread
view the rest of the comments
[-] MissingInteger@lemm.ee 6 points 1 year ago

So you linked to apt.
I guess good for anyone who finds this interesting…
But more on topic here is is a link to answer from 2020 from an flatpak maintainer:

If a user installs or updates a specific app-id the code verifies that:

  • The new app is gpg signed by a trusted key
  • Checksum verifying that all files are untampered with
  • The new app has that app id
  • The new app has a later timestamp on update
[-] jagged_circle@feddit.nl -2 points 1 year ago

Link me to the docs that say this

[-] MissingInteger@lemm.ee 5 points 1 year ago

You are not arguing in good faith.
I have linked multiple times to the docs and to the GitHub repository of flatpak.
Now how about you link to something useful in the docs that proves your point or maybe just a random article as source to your misinformation.

[-] jagged_circle@feddit.nl -2 points 1 year ago

You have failed to find a doc that say signatures are required to be valid on the client for everything it downloads.

This software isn't secure. You can live in la-la land, pretending it has features it doesn't, but that doesn't change the facts.

this post was submitted on 15 Feb 2025
190 points (98.5% liked)

Linux

12320 readers
423 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 2 years ago
MODERATORS