3 ms·
I wish most Linux distributions had something like a standardized permission manager in which you enable the single policies apps are running with, similarly to
by Lucasoato 21d ago
I wish most Linux distributions had something like a standardized permission manager in which you enable the single policies apps are running with, similarly to what happens in Android (that has some Linux stuff under the hood).
How hard would it be to have something like this? And I can’t even imagine the difficulty of gathering together the whole community around this standard...
- hulitu 21d ago> similarly to what happens in Android Do you wish to give this app access to _all_ your {files, photos, phone calls, messages} ? /s What do we need permissions for, then ? Let MS-DOS come back.
- Lucasoato 21d agoActually we should have something like iOS in which you can allow an app to access certain images (or whatever), or manage the images it generates.
- monomania 21d agoIt'd be easy, just build it into systemd. .../s
- theshrike79 20d agosystemd-clipboardd? What could be better!
- jthoward64 20d agoJokes on you, systemd-appd is in planning stages right now.
- samus 21d agoQuite hard because on Linux there is no concept of "apps". There is a (very flimsy) separation between processes, but the strongest actual security boundaries are between kernel and user space as well as between users. Namespaces are explicitly not acknowledged as such, which limits the security guarantees that containers can provide. Snaps and Flatpak are steps towards that goal, but there are many issues surrounding these technologies, and many apps require sweeping permissions to work well since they were not initially designed to be limited in that way.
- kd913 21d agoSnaps are a lot lot better in this regard especially in the perspective of connections. You can define connections to home, camera, network etc... I have not seen the same in flatpak.
- vyskocilm 21d agoSure flatpak have a static permission system too, even it is not recommended and xdg portals are the way of integrating with a host. https://flathub.org/en/apps/com.github.tchx84.Flatseal https://flathub.org/en/apps/com.github.tchx84.Flatseal
- phendrenad2 21d agoI don't get why a big company like Zoom, with presumably lots of users who are on Linux, only gives us a .rpm/.deb instead of a Snap/Flatpak. Seems like doing the minimum.
- NekkoDroid 21d agoSnaps is a sure-fire way to only get used on Ubuntu. So that would be worse than distributing .rpm/.deb.
- phendrenad2 21d agoIt's possible to distribute more than one format.........
- zbentley 21d ago> How hard would it be to have something like this? Very. Both because of the technical issues others in this thread mentioned, and because Android and iOS had the unutterably massive advantages of starting from zero pre-existing software and having a single controlling authority. The controlling authority allowed them to avoid problems related to consensus or people working on other priorities. Starting from zero allowed them to not worry about existing software (the closest thing to a controlling authority that Linux has cares a lot about backwards compatibility).
- fsflover 20d agoIt looks like you are searching for Qubes OS.