4 ms·
This seems to miss the article's point. You wrote: > I don't think [running apps directly as OS packages] is more secure than [running apps via flatpac] The
by codesections 6y ago
This seems to miss the article's point. You wrote:
> I don't think [running apps directly as OS packages] is more secure than [running apps via flatpac]
The article's claim is that running them via flatpak _is_ less secure because they don't automatically get security updates when the distro's libraries are updates and, as a result, they're less likely to receive prompt security updates. Do you disagree? If so, why?
- boudin 6y agoFor non open source software, dependencies are often packaged with the software itself, so it would be the same in flatpak or in the distro. It is true for software that uses shared libraries though.
- dathinab 6y agoBut they also use a lot of system libraries. E.g. they likely will not bundle openssl but use the systems openssl.
- pelasaco 6y agowhat I don't like with installing it from distro is to pollute my OS and full my /usr/bin with some user app that should live on my /home. But i agree that the security updates are a real issue.
- Spivak 6y agoThe Flatpak model is good for "pet apps" where you have a company, team, project whose entire job is to make this one app. Relying on upstream to fix security vulns is less of an issue because these companies have incentive to fix them. Spotify, Teams, Skype, Bitwarden, Slack are all pet apps. The Flatpak model is terrible for distros who are already strained for people and who benefit from factoring as much of the work as possible out of each application so you only have to update one place and push out a fix everywhere.
- cheph 6y agoIf I could get the same things from distro I would maybe be more inclined to use distro packages, but in many cases I cannot. My distro either does not have the things I use from flatpak or have them with some deficiency (like older version or compiled features). I can still get rpms for some, like Teams, but that also comes with bundled libraries and the Teams flatpak does have very tight restrictions so if I am concerned for the rest of my system flatpak is more secure. For some other things on that list there are no rpms however. So yes, you are more exposed to the maintainers behaving well, but you are also more insulated than just running things without any sandboxing.
- pnutjam 6y agoWell, the sandbox is a lie. Did you RTFA? Plus, you can have rpms that provide their own packages, but it's rare and will still be upgraded if it's in the repos.
- cheph 6y ago> Well, the sandbox is a lie. It's not though. And for Teams filesystem access is serverely restricted only allowing access to xdg-downloads.
- SEJeff 6y agoBut it is kind of a moot point, because you can update the flatpak stuff. I run dnf update -y to update the packages on my fedora laptop and flatpak update -y to update my flatpaks. It updates signal and the fedora platform libraries (security updates anyone?).