5 ms·
When Flatpak's Sandbox Cracks
- forty 1y ago[flagged]
- kstrauser 1y agoI never understand these comments. This adds nothing to the discussion. And as the editor of Linux Journal, I bet George has written plenty of bullet lists over the years. Maybe the AIs are copying him, you know?
- duskwuff 1y agoIt's an expression of concern - is this article actually an expression of someone's thoughts about a topic of concern, or did someone just ask ChatGPT to write them an article about Flatpak security?
- kstrauser 1y agoA great way to address those concerns would be to look at the reputation of the person being questioned, who in this case is the editor of Linux Journal. That doesn't prove he'd never use AI, but it does mean it's not some random blogger trying to sell their reputation for cheap karma before anyone notices. But really, I don't care. I'm far more annoyed with people racing to cash in with "this looks like it was written by AI" on every. single. post. Yeah, we get it. It does not make the accuser look more clever or insightful. It makes them look like a pest.
- duskwuff 1y ago> That doesn't prove he'd never use AI, but it does mean it's not some random blogger trying to sell their reputation for cheap karma before anyone notices. It wouldn't be the first time I've seen a formerly reputable web site start churning out AI slop, unfortunately. And, for what it's worth, this other article on the site, published a few days ago, doesn't fill me with confidence either: https://www.linuxjournal.com/content/veil-vigilance-tails-60s-new-frontiers-surveillance-resistance https://www.linuxjournal.com/content/veil-vigilance-tails-60... It's mostly a paraphrase of the official release notes (https://blog.torproject.org/new-release-tails-60/ https://blog.torproject.org/new-release-tails-60/), and it's over a year late - Tails 6.0 was released in February 2024. Even if it's human-written, it's a weird topic to choose and an extremely lazy way to write about it.
- kstrauser 1y agoI’m not saying he’s a great author, just that it’s ridiculous to accuse him of that because he uses bullet points.
- freedomben 1y agoIndeed, I've been making bullet point lists like that since college when I had a communications professor drive it into our heads. Yes AI loves the bullet point list, but just including one does not make it AI. This is yet another step on the overall reduction in quality of writing. Now we have to avoid bullet point lists, and inject typos and other things into our writing to make it seem more "human." It's a road to sadness and the dumbing down of society IMHO.
- forty 1y agoI'm surprised that someone would came to the rescue of bullet points for the sake of defending quality writing as they seem to me exactly the opposite of quality writing, but I guess this could be a matter of taste
- hollerith 1y agoI agree. I've been annoyed by bullet points (exceptions: instruction manuals and lists of ingredients in recipes) starting well before AIs started writing text. Thankfully, so far the LLMs in my life will avoid bullet points if I ask them to.
- WesolyKubeczek 1y agoI can speak in listicles and use em-dashes — correctly, mind you! — using only organic neurochemistry-based intelligence of my brain.
- WesolyKubeczek 1y agoFlatpak's "sandbox" is mostly theater, and it gives little when it comes to privacy. Apart from the obvious that packages sometimes come with overly broad permissions to be usable at all (but you are still given a marketing pitch about enhanced safety, granted, flatpak.org doesn't do it but flathub does), the fact that some paths are denied or some access is revoked is also a data point. I'd like to have a system where I can choose to give any bitmap, movie, or blank screen when an application asks me for permission to use my camera. It shouldn't know that I have denied it. When it asks for my microphone, I should be able to choose to make it think I allowed it microphone access with dummy audio stream with no audio or audio of my choice. When it asks me to open a file, or a directory, it should invoke a system dialog that cannot be faked, and when I pick a file/directory for it, that directory or file should be bind-mounted into its mount namespace without giving it extra information about other files beside it, or indeed what's the full path of the file. When recording a screen, I should be able to pick which regions and which applications it should be able to see, and the system should make it think it's all there is. All the while the application doesn't even have to cooperate. This is the important bit. I think the pieces to do this are mostly there already (portals, Pipewire, namespaces), it's just a lot of faff to actually implement.
- bestorworse 1y agoI want that as well, but I don't think it's practical to do that on the Linux desktop ecosystem. Too slow, too much politics. The gist of it is done by Android though, but that required extensive re-engineering of the user space. Risking getting down voted but I don't want to repeat myself: https://news.ycombinator.com/item?id=43255985 https://news.ycombinator.com/item?id=43255985
- freedomben 1y agoI would love the capabilities you describe, but I don't think it's fair to call flatpak "mostly theater." Yes plenty of flatpak apps require you to broaden their perms to the point where the sandbox starts to feel pretty weak, and there is plenty more to do on the system, but I think it's a good step forward.
- AlienRobot 1y ago
- fake-name 1y agoFlatpak, Snap, appimage, etc... I have pretty fastidiously avoided ever using any of the "package everything into the image" projects, and my life has been considerably better off. All these things serve to do is make the developer experience easier, at the cost of delivering a much worse user experience. I can't think of any reason a user would ever prefer packaged variant of something.
- jwrallie 1y agoIt is better when you cannot get a package otherwise, so if you use a distro with a big repo, it happens mostly with proprietary software.
- xorcist 1y agoMost proprietary software ships as tgz files which you can just unpack and run. A few ships with "installers", which are mostly just bash scripts with the tgz embedded. Simple enough.
- TingPing 1y agoIf you pretend dependencies don’t exist. Binaries aren’t portable.
- xorcist 1y agoFor all practical purposes they mostly are. Linux famously hasn't broken userspace in over thirty years. Pretty much all commercial software for unix (and Linux) is distributed this way since several decades. Things like ld-linux.so is mostly backwards compatible for this reason. You can still run ancient Firefox builds even if you might have to fetch an old libstc++. But those are still around, for exactly that reason. Of course, the world changes. Running X11 software might be tricky a few decades from now if nobody speaks the protocol. Something compiled for ALSA or esound might not work forever. Software dependent on a mail transport might not work when email is finally dead and everyone uses Facebook instead. Perhaps one day IPv4 sockets won't be available. That type of dependencies are the hard ones that will kill your software before any binary incompatibilities will. As long as there is a.out binaries or 32-bit software out there someone will make it work. Software from the past three decades still runs so there's hope for the next three. Until then, don't let perfect be the enemy of what's simple and works.
- ChocolateGod 1y agoA lot of Flatpak applications ship with filesystem=home, and this is effectively opens up ways of indirectly getting root access (since you can override sudo by editing .bashrc) or overriding .desktop files (of say system settings) to point to your application instead which a user is more likely to enter their password when opening, or override environmental variables, you get the picture. It's not as if non-Flatpak apps can't do this either, but the false sense of security from Flatpak may encourage people to download apps they wouldn't otherwise. Unlike Android/iOS where Google/Apple can push developers to update their apps to use new apis, or say bye bye to those that don't, there's no motivation for Linux app devs to update their applications to use portals to avoid the need for filesystem=home, and as long as that exists people will just install them with a false sense of security. Flatpak is not a security project, it's an app distribution one (which I think it does a generally better job than native packages, but the bar is low). The sandbox should be considered part of the separation from host dependencies, nothing else.
- BrenBarn 1y agoPersonally I'd just as soon have something that is like Flatpak but without the security pretensions. The main advantage for me is just being able to update each program independently of an OS-level package repository.