4 ms·
Quite hard because on Linux there is no concept of "apps". There is a (very flimsy) separation between processes, but the strongest actual security boundaries a
by samus 20d ago
Quite hard because on Linux there is no concept of "apps". There is a (very flimsy) separation between processes, but the strongest actual security boundaries are between kernel and user space as well as between users. Namespaces are explicitly not acknowledged as such, which limits the security guarantees that containers can provide.
Snaps and Flatpak are steps towards that goal, but there are many issues surrounding these technologies, and many apps require sweeping permissions to work well since they were not initially designed to be limited in that way.
- kd913 20d agoSnaps are a lot lot better in this regard especially in the perspective of connections. You can define connections to home, camera, network etc... I have not seen the same in flatpak.
- vyskocilm 20d agoSure flatpak have a static permission system too, even it is not recommended and xdg portals are the way of integrating with a host. https://flathub.org/en/apps/com.github.tchx84.Flatseal https://flathub.org/en/apps/com.github.tchx84.Flatseal
- phendrenad2 20d agoI don't get why a big company like Zoom, with presumably lots of users who are on Linux, only gives us a .rpm/.deb instead of a Snap/Flatpak. Seems like doing the minimum.
- NekkoDroid 20d agoSnaps is a sure-fire way to only get used on Ubuntu. So that would be worse than distributing .rpm/.deb.
- phendrenad2 19d agoIt's possible to distribute more than one format.........