3 ms·
You will most likely get a malicious AppImage from some website because there is no default central store with such packages. You could argue that there is a f
by simosx 7y ago
You will most likely get a malicious AppImage from some website because there is no default central store with such packages.
You could argue that there is a freedom with AppImage that you are not bound to a Store. But that would not be correct, because you can self-host both snaps and flatpaks, if you really need to.
With snaps, you have more fine-grained security privileges. For example, "httpstat" [1] is a network utility to benchmark the access to a website. As a utility, it only requires access to the network. With snaps, the packager can only permit access to the network, and no access at all to the user's files or anything else.
1. https://github.com/davecheney/httpstat https://github.com/davecheney/httpstat
- app4soft 7y ago> is no default central store with such packages And this is limitation of Snap and Flatpack - both stored in centralized stores. AppImage is fully independent from any centralized stores, so developers could distribute own apps as AppImage-package directly to users.
- the_why_of_y 7y agoSnap is centralized; anybody can host their own Flatpak repo, it's just files served over HTTP. https://blogs.gnome.org/alexl/2017/02/10/maintaining-a-flatpak-repository/ https://blogs.gnome.org/alexl/2017/02/10/maintaining-a-flatp...
- simosx 7y agoI said that there is no "default" central store for package in AppImage. Which means that there is a "default" central store for snaps and flatpaks. And if you do not like the "default" central store, you are free to distribute yourself the individual snap or flatpak package. Just like with AppImage.
- AnIdiotOnTheNet 7y agoSure... by making the user setup the equivalent of a PPA. AppImage's advantage is that you can mail it to them on a CD and they can just run it from the CD.
- simosx 7y agoDamned if you do, damned if you don't. Regarding the reference to "like mounting the CD ISO" for AppImage. All three of them actually mount one or more filesystems in order to install the package.
- loginwithgithub 7y ago"You will most likely get a malicious AppImage from some website because there is no default central store with such packages." - No. Just no. If you download the AppImage directly from its original author's website, then you know that no one has tampered with it and it is exactly as the original author intended. In contrast, look at Flathub. Most applications there are not provided by their original authors, but by "random guys". Who do you trust more?