3 ms·
In my opinion as someone who just uses these Linux DEs, it seems like it would be better if they focused on “safe” content and left anything scriptable to be di
by _23sd 3y ago
In my opinion as someone who just uses these Linux DEs, it seems like it would be better if they focused on “safe” content and left anything scriptable to be distributed through other means. The security risks along with bad experiences with outdated and broken software in the past have convinced me to never use these features, which is a shame as people have probably made some neat themes and widgets. On the post, I don’t buy the comparison with AUR and PPA. Whatever the risks with those systems (and don’t get me wrong, they can be significant), the end user has usually concluded based on reputation from elsewhere that they want to install a particular application and they use the AUR or PPA system to get the job done. The theme stores on desktop environments, by contrast, seem like they’re going to be the way that users discover small pieces of content that are never going to have much of an external reputation. To use such programs safely you would have to read the source code of anything you’ve thinking about using, and not many people have the ability and time/willingness to do so.
- ndiddy 3y agoWith the AUR and PPAs, random members of the community that weren't involved with developing the original software can submit software. This means you can't go off of the software's reputation alone, as someone may have uploaded a malicious version of existing software (i.e. what happened around a month ago on the Ubuntu Snap store with a malicious Bitcoin wallet: https://popey.com/blog/2024/02/exodus-bitcoin-wallet-490k-swindle/ https://popey.com/blog/2024/02/exodus-bitcoin-wallet-490k-sw...). I do agree that themes don't sound like they could execute code, and KDE should be doing more to restrict what they can do to a user's computer.