top 50 comments

sorted by: hot top controversial new old
[–] 255 points 2 years ago (3 children)

It's not fully sandboxed if it can write to my screen! That filthy app, writing stuff all over the place!

  • source
  • hideshow 3 child comments
  • [–] 148 points 2 years ago (37 children)

    What if your app actually needs access to the internet?

  • source
  • hideshow 37 child comments
  • [–] 166 points 2 years ago (19 children)

    Or actually do anything useful? No network, no filesystem.. it's a hello world app isn't it..

  • source
  • parent
  • hideshow 19 child comments
  • [–] 37 points 2 years ago (4 children)

    Oh come on, what modern program actually needs to communicate or access the file system?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 25 points 2 years ago (9 children)

    Download the internet along with it!

  • source
  • parent
  • hideshow 9 child comments
  • load more comments (1 reply)
  • load more comments (1 reply)
    [–] 136 points 2 years ago (2 children)

    I like how the app name is blacked out so as not to dox the flathub app.

  • source
  • hideshow 2 child comments
  • [–] 61 points 2 years ago (10 children)

    What really needs to happen:

    Flatpak packages should ask for every permission they need, and the user needs to approve every one of them.

    Right now, we have this weird in-between state where some flatpak packages ship with limited permissions (like Bottles). That's because every permission the package asks for is immediately granted. The user doesn't get a chance to refuse these requests. This current model serves to make life more difficult for non-malicious flatpak packagers while failing to protect users from malicious packages.

    Also, GNOME needs a Flatpak permissions center like KDE. You shouldn't need to install a third party program to manage permissions.

  • source
  • hideshow 10 child comments
  • [–] 8 points 2 years ago (1 child)

    I've tried to combat this a bit with a global Flatpak override that takes unnecessarily broad permissions away by default, like filesystem=home, but apps could easily circumvent it by requesting permissions for specific subdirectories. This cat-and-mouse game could be fixed by allowing a recursive override, such as nofilesystem=home/*.

    But even then, there is still the issue with D-Bus access, which is even more difficult to control ...

    I think it is sad that Flatpak finally provides the tool to restrict desktop apps in the same way that mobile apps have been restricted for a decade, but the implementation chooses to be insecure by default and only provides limited options to make it secure by default.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • load more comments (2 replies)
    [–] 47 points 2 years ago (2 children)
  • [–] 35 points 2 years ago (2 children)

    This kind of thing could work for a few apps, say a color picker utility or a QR code generator etc.

    Looking at the docs, it isn't clear if apps can write to their own namespace (instead of writing to user folders directly), but if they can, we could expand the scope to games like supertuxkart, 2048 etc, which would then be able to save user milestones and progress in their own area - a bit like how Android apps do it

    https://docs.flatpak.org/en/latest/sandbox-permissions.html

    It's a great start IMO, although admittedly there is still work to do. Flatpak atm bridges the gap with allowing new apps, requiring new libs, to run on older stable/LTS distros

  • source
  • hideshow 2 child comments
  • [–] 33 points 2 years ago (8 children)

    Likes like Hello World is ready to ship.

  • source
  • hideshow 8 child comments
  • [–] [S] 27 points 2 years ago* (7 children)

    With a bit of modifying code to use the color picker and maybe rearranging the workflow to adapt to the new system, apps as advanced as DaVinci Resolve and LibreOffice can have permissions as restrictive as this (the network permission would of course may be needed but it would still be marked as Safe by Flathub).

    You can use the file picker API to open the files or folders your app would need to access while having no filesystem permissions at all. You can access the camera, microphone, and GPS without the user devices portal, by simply using the respective portals where the user has the power to allow or deny access to such devices as they wish.

    You can record the screen, take a screenshot, and pick a color in the screen by simply calling the proper portals, with the bonus that the user will be able to select if they want the entire screen, a specific window, or a specific area to be recorded/captured and whether the cursor should be shown or not.

    Heck, even TeamViewer can be as this restricted without losing any functionality if they use the Screen Cast portal which allows apps to mirror input from a remote device! They would of course need the network permission, but that's still safe.

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (7 replies)
  • [–] 27 points 2 years ago

    this sandbox craze is slowly pushing things back to the point where we used cartridges and booted off from them straight to the program. who needs an OS at this point? it's bundled with the app anyway 😆

    /s, somewhat

  • source
  • [–] 22 points 2 years ago (1 child)

    It's nice to see good app security being praised. Sometimes it feels like some people on lemmy (and the fediverse) throw security to the wind.

    Like one time I had heard someone over on Mastodon say that they thought that HTTPS was too overused and shouldn't have been everywhere because it makes older apps unable to access sites and also made adblocking just ever so slightly harder.

    Which yeah, I love adblockers, but I'm definitely not comfortable with all traffic having to go unencrypted just for it.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 20 points 2 years ago (1 child)

    This is useful for proprietary software.

  • source
  • hideshow 1 child comment
  • [–] 12 points 2 years ago (3 children)

    What is this? A solitaire game?

  • source
  • hideshow 3 child comments
  • load more comments
    view more: next ›