158
submitted 3 weeks ago by [email protected] to c/[email protected]
you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 0 points 3 weeks ago

Ah okay, thanks for the clarification! I haven't delved deep into that aspect yet. But I've recently become aware of this unaddressed attack vector. And it is definitely something to worry about.

Unsure if it's solved anytime soon. But, if it is properly addressed and solved at some point in the future, would that (completely) redeem Flatpak's security model? Or, at least make it superior to what's found elsewhere?

[-] [email protected] 1 points 3 weeks ago

They don't seem to give a shit about security. I think the well is poisoned. Best to just use apt

[-] [email protected] 1 points 3 weeks ago

They don’t seem to give a shit about security. I think the well is poisoned.

Nah, I wouldn't go that far. That's like way too dramatic.

Best to just use apt

I will whenever apt doesn't (majorly) rely on backports for its security updates AND actually sandboxes its own packages. Zero Trust, FTW!

[-] [email protected] 1 points 3 weeks ago* (last edited 3 weeks ago)

When a critical security bug is open for years on a project with plenty of funding to fix it..

this post was submitted on 02 Jun 2025
158 points (97.0% liked)

Linux

8093 readers
1004 users here now

A community for everything relating to the GNU/Linux operating system

Also check out:

Original icon base courtesy of [email protected] and The GIMP

founded 2 years ago
MODERATORS