5 ms·
So I run Kubuntu on my work laptop (X1 Carbon) and just upgraded to 20.04 last weekend. I had a vague idea there were different competing standards for "linux a
by stevepike 6y ago
So I run Kubuntu on my work laptop (X1 Carbon) and just upgraded to 20.04 last weekend. I had a vague idea there were different competing standards for "linux apps that work across distribution" but didn't know people had such a problem with snap. It just seemed like a useful tool for installing proprietary stuff that wouldn't normally be packaged by the distribution. I just checked and the snaps I have that aren't from canonical are: datagrip, slack, discord, and spotify. I haven't noticed any slow app boot times and I think it's great that it's so easy to install third party software. Is snap somehow user-hostile?
- blacksmith_tb 6y agoThere are some downsides (footprint, forced updates, speed, etc.), though depending on what you're installing those may not be deal-breakers. I'm using plain Ubuntu 20.04 and I tend to install stuff via apt and not snap in general (but I am fine with installing non-essential things via snap). The software store has a subtle toggle in the upper right for choosing to install a package as a snap or via apt when both are available.
- stevepike 6y agoYeah, is there a plan for it to long-term replace apt? I've just always used apt as my first choice and then snap for random things like spotify.
- toyg 6y agoThey are making a very big bet on snap, I would expect most of their desktop apps to be slowly moved there in the next few years. At that point apt would be kept around strictly for essential system packages and (hopefully) for server usage.
- RMPR 6y agoImho the principal downside (which you didn't mention) is the vendor lockdown.
- excalibur 6y ago> Is snap somehow user-hostile? Yes, but more importantly it's insecure. The ease of typo-squatting is a real problem.
- lucb1e 6y agoIsn't using the internet insecure then? I can typo bankname.example.nl as well. Not that I don't see your point: a curated list like the repositories is preferable to a system where anyone can claim any name, but I am not sure that this extrapolates to the statement that "it's insecure" as a whole. Out of interest (I don't use Ubuntu/snaps myself), is that really the case? Can I actually a publish <insert popular package> without any checks and, once I got half a million users by repackaging the deb file in snap, add some subtle malware? There is no review process or anything?
- timClicks 6y ago> Can I actually a publish <insert popular package> without any checks and, once I got half a million users by repackaging the deb file in snap, add some subtle malware? There is no review process or anything? This is already possible with every other distribution method. If you host your own debs, then you can easily get them to do whatever you want. Even relying on the main archive isn't great - apt is typically delivered over HTTP to make mirroring easier, for example.
- lucb1e 6y ago> apt is typically delivered over HTTP This is a large misunderstanding of how it works. You can't MITM millions of servers around the world just because they use HTTP for downloading their apt archives. It verifies the cryptographic signatures. That's why you need to "apt-key add" when you add a custom repository. It doesn't rely on the transport method for integrity. > [Typo-squatting] is already possible with every other distribution method. No, the counterpoint we're talking about is apt. In apt, not anyone can just register any package name. My question was whether that's really a thing in snap. > If you host your own debs, then you can easily get them to do whatever you want. I'm not quite sure what you're trying to say here. Why would I host my own deb files (in the first place, but even if I did) only to hack myself? I could just install the modified deb files directly or modify the files on-disk, no hosting needed?
- koheripbal 6y agoIt's insecure-by-default. ...which in my mind means it's not really even Linux (hyperbole).
- bdamm 6y agoHow is it insecure-by-default?
- koheripbal 6y agoBecause on an Ubuntu Server, it's auto-deploying updates that I haven't even tested.
- bdamm 6y agoThat's not insecure-by-default, that's just you having a (legitimate) issue with the distribution chain. Insecure-by-default is installing software that has known weaknesses. That the process doesn't work for you doesn't mean the software is weak.
- gfxgirl 6y agoAre they sandboxed individually? If not it's insecure by default. I mostly don't mind auto-updates on iOS and maybe Android as they're at least supposed to be each app sandboxed by default. MacOS is getting better at this. Windows sucks at it. Where is snaps on that spectrum?
- ClumsyPilot 6y agoAre you alluding to possibility of an update containing malicious code? Is that because the update's authenticiry is in question or is that because of original developer went rogue? Leaving the system unupdated is insecure. I do not see how auto-updates make it insecure, but themselves.
- 6y ago