3 ms·
which is to say, trusted sources over technical solutions This does not solve the problem where your a PDF reader from a trusted repository happens to have a z
by danieldk 6y ago
which is to say, trusted sources over technical solutions
This does not solve the problem where your a PDF reader from a trusted repository happens to have a zero day exploit. When it is exploited, the attacker could have access to all your files, since there are no further limitations unless you bubblewrap or firejail the application yourself.
Since sandboxing is one of the goals of Flatpak, the exploit would be limited to the sandbox (if sandboxing was enabled for the PDF reader).
- hkt 6y agoIt doesn't solve that problem, but it does provide a channel that is likely to receive an update in most distributions. It would be nice to not have to choose between sandboxing and security updates, though.
- danieldk 6y agoI agree, but nobody seems to be really working on (user-friendly) sandboxing of applications distributed through traditional package managers. You can use Firejail or bubblewrap, but they are not exactly user-friendly solutions.