4 ms·
This is like saying that bicycles are a major degradation from traditional mobile systems like cars, because they have no airbags and no ABS. The threat model
by john61 3y ago
This is like saying that bicycles are a major degradation from traditional mobile systems like cars, because they have no airbags and no ABS.
The threat model for linux phones is completly different, since they use free software und hardware wherever possible.
- l72 3y agoAgreed. Having use linux and FOSS since the late 90s, it is interesting to see how much we've had to lock down mobile devices and proprietary operating system because we can't trust the applications (and in some cases, the OS) that run on them anymore. My Linux laptop runs all open source software, from "trusted" sources. My pinephone runs all open source software from "trusted" sources. If I don't trust Fedora or Alpine, I can download the source rpms and build them myself. My devices still give _me_ control over them, and allow _me_ access to inspect what my applications are doing. If I am paranoid, I can run `lsof` or `strace` and see every file touched by an application. I can monitor my network and see ever egress host. It is a completely different threat model than you would have with an Android or iOS device, where you have no trust in your applications or ability to inspect what is happening on your device.
- deleted 3y ago[deleted]
- jraph 3y agoMostly agree, though isolation is still useful against security flaws. You access untrusted content with software you trust but which might be imperfect. I wouldn't mind a bit of isolation between apps on my Linux desktop (and phone). I would mind the cost of bringing one or several additional copies of a Linux system and degraded performance though, so I'm not a fan of Flatpak for this reason.
- l72 3y agoDo you find that you really have degraded performance with Flatpak? On my pinephone running postmarketos, all my non system applications are from Flatpak, which allows sandboxing and easy updates. I can't say I've noticed any performance differences (unlike with Snap last time I tried it).
- jraph 3y agoI think that when the app is actually running, it runs fast, but boot time is higher, and I suspect increased memory usage. I end up not installing a lot of Flatpak apps because of disk space usage anyway. Each package choose a different base system so they end up sharing nothing and taking hundreds of megs each, it's quite annoying. On the PinePhone I only have OSM Scout Server and Pure Maps installed like this, and that's really because there are no Debian packages for them.
- Bu9818 3y agoThe only performance impact I know of is with the seccomp filter in CPU-bound tasks: https://github.com/flatpak/flatpak/issues/4187 https://github.com/flatpak/flatpak/issues/4187 Skimming through the recent comments, there might be a way to optimize some of it.
- ngcc_hk 3y agoNot 100% sure that open meant security. It can be spotted and traced no doubt. But harm still can be done. This is particularly if they’re a web of dependence. If one goes … It is nicer to be open. But it is not paradise.