Live data from Hacker News

Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

jatan.blog

541–550 of 645 posts

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#541

Earlier quoted context omitted.

...dumb question: Does this apply to Ubuntu Server as well??? Because if so, I'm sticking with 18.04.

only if you install your server applications using snap

So, why are people getting upset about this then? If you can simply just _not use snaps_?

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#542

Earlier quoted context omitted.

It's probably not a surprise to you, but this is a hotly debated topic inside Canonical. And I apologize for that thread, as it really doesn't represent our best attempt at external debate. Changing a paradigm usually involves pushing the envelope and breaking some existing assumptions; systemd is everybody's favorite example of that in the Linux world. The root of this issue with snaps is the trade-off between built…

The the very least there should be a simple way to turn off snaps entirely. As in, when installing do we want any snaps? If we don't, don't even install the snap ecosystem. After install, have I decided I don't want snaps? If so, uninstall the entire ecosystem. Do these options currently exist?

The challenge is that a) we don't really want to (can't afford to, etc) maintain a forked package for everything which comes in snaps and b) snaps are really, really, much better for publishing and maintaining certain classes of application, in particular complex ones with hundreds of dependencies and a massive surface area, like a web browser. And users want web browsers, so the default is to include snaps.

In general, you can opt of snaps entirely and `apt-get remove snapd`, but you'll miss out on potentially critical components that are only available via snaps.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#543
post #515

Earlier quoted context omitted.

It's probably not a surprise to you, but this is a hotly debated topic inside Canonical. And I apologize for that thread, as it really doesn't represent our best attempt at external debate. Changing a paradigm usually involves pushing the envelope and breaking some existing assumptions; systemd is everybody's favorite example of that in the Linux world. The root of this issue with snaps is the trade-off between built…

Why not at least have an option per install to control the update behavior? I might want the latest Chrome and Firefox. But I don’t necessarily want the latest update to other applications.

I think this is a great suggestion, and I would also prefer that you could just permanently disable (via config, even if somehow discouraged) the default auto-update behavior.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#544
post #449

Earlier quoted context omitted.

I'm surprised that something like routing software is/was being distributed via snap instead of as a Docker container; snap seems much more targeted towards end-user workstations than to servers.

I always felt that snap was designed for servers with desktop being an afterthought (thus why so many things still don't work in snap, ex: sys gtk themes). Flatpak on the other hand was designed desktop first and barely works for server stuff. But the Flatpak experience on the desktop is vastly superior to the snap one IMO.

Actually, snaps inherit from Ubuntu Phone's app packaging mechanism, so it's neither server nor desktop — but certainly closer to the end-user side of the spectrum.

(For server apps, the auto-update mechanism has a really painful consequence, which is that for clustered apps you have a built-in race condition that might kill your cluster)

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#545

Earlier quoted context omitted.

Debian runs on everything I've come in contact with, or virtualized. Debian's problem is that it's stodgy updating policy means 'Stable' is still on 4.19, things like Wireguard require a simple, but odd procedure to request apt pull packages from newer releases, and most of the copy/pasteable examples out there assume Ubuntu, and their versions/customization to critical infrastructure packages. IMHO, the stodgy updat…

> things like Wireguard require a simple, but odd procedure to request apt pull packages from newer releases That's not a good idea, as it breaks the assurance that Debian Stable provides. Using the backports repository is the recommended approach if you need a newer version of some clearly-defined piece of software. It will pull the newer dependencies it requires from backports, while still relying on stock-provided…

It's not a good idea, but Debian's wiki is nevertheless recommending it: https://wiki.debian.org/WireGuard

I tried it. Long story short, now I'm on Sid.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#546
post #421

I am very diligent about applying updates as soon as I'm able and generally read the changelogs of the updates I'm applying in Ubuntu's Software Updater. One thing I will not do is willingly allow somebody else a way to deploy and execute code on my computer without my say so (which snap is). After reading the whole thread at https://forum.snapcraft.io/t/disabling-automatic-refresh-for... and seeing Gustavo Niemeyer'…

It's probably not a surprise to you, but this is a hotly debated topic inside Canonical. And I apologize for that thread, as it really doesn't represent our best attempt at external debate. Changing a paradigm usually involves pushing the envelope and breaking some existing assumptions; systemd is everybody's favorite example of that in the Linux world. The root of this issue with snaps is the trade-off between built…

> The root of this issue with snaps is the trade-off between built-in security and user control.

What this tells me is that I am not the kind of user you are targeting. I don't either need or want any such trade-off. I'm knowledgeable enough to make my own decisions about security; I don't need a third party to do it for me. So if your distro will end up insisting that I cede any control over what software runs on my machine to a third party, it's a nonstarter as far as I am concerned.

That may or may not change your overall strategy, and I emphasize that it's your decision either way and I would not have a problem if your response is simply: "Well, we are targeting a particular kind of user and that's just the way it is." (I would simply go find another distro to run.) But I think you need to be clear about what kind of users you are targeting and what kinds of control you expect those users to give up to third parties, so users know what they are getting into.

I also think that this idea of having third parties control the security of your computer is against the basic Unix/Linux philosophy, because the whole point of running Linux or some other variety of Unix is to opt out of the walled gardens and third-party controls that other operating systems that I won't name force users to accept. So if you're going that route, IMO you're going to have a tough time explaining to users why they shouldn't just go ahead and run one of those other operating systems instead.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#547
post #391

Earlier quoted context omitted.

+1 Insightful. > GNOME Calculator was put on the ISO as a snap to help us test the whole “seeding snaps” process, not because it was a fast-moving, CVE-prone applications. Chromium, Firefox and LibreOffice fall more into that category. Ok so the whole snap thing comes down to updating browsers. Is this for real? I want the web, not the browser to change daily, or to consume more bandwidth than my www usage :)

The browser is actually the number one component you should update as soon as a security fix comes out. If you don't want new features ("more free stuff!"), use an LTS version that only includes the security updates?

> The browser is actually the number one component you should update as soon as a security fix comes out.

The problem is that there is no way to have a browser that only pushes updates for security fixes. They're always mixed in with changes to the UI that force people to re-learn workflows.

> If you don't want new features ("more free stuff!"), use an LTS version that only includes the security updates?

There is no such thing. I run Ubuntu 16.04 LTS on all my computers at home and I'm posting this on, IIRC, the fifth or sixth new version of Firefox I've had to accept (and that's only counting major version changes), because, as noted above, there was no way to just get the security updates and leave out the others.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#548

> Snap applications auto-update and that’s fine if Ubuntu wants to keep systems secure. But it can’t even be turned off manually. OMG. Is this real? This is the exact reason I use Linux instead of Windows 10 or macOS. I am not a grandma who can't stay up to date on tech news. At the least there should be a toggle for power users. But no, you can only defer it. Am I the only one who doesn't like it when your already s…

I just upgraded to 20.04, and minutes later my machine is on its knees OOMing and unable to process remote connections. Apparently there is now yet another new file system indexer to play whack-a-mole with like updatedb in the old days except this one is hooked into systemd and harder to stop. Search for "tracker-extract disable" if you want the full details.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#549

Earlier quoted context omitted.

The the very least there should be a simple way to turn off snaps entirely. As in, when installing do we want any snaps? If we don't, don't even install the snap ecosystem. After install, have I decided I don't want snaps? If so, uninstall the entire ecosystem. Do these options currently exist?

The challenge is that a) we don't really want to (can't afford to, etc) maintain a forked package for everything which comes in snaps and b) snaps are really, really, much better for publishing and maintaining certain classes of application, in particular complex ones with hundreds of dependencies and a massive surface area, like a web browser. And users want web browsers, so the default is to include snaps. In gener…

I'd argue you can't just "apt-get remove snapd", when you push transitional apt packages that depends on snapd.

I understand the argument with browsers, but that does not justify the default on ubuntu-server. LXD being Snap-only really feels like force-feeding Snap.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#550

Earlier quoted context omitted.

Are they sandboxed individually? If not it's insecure by default. I mostly don't mind auto-updates on iOS and maybe Android as they're at least supposed to be each app sandboxed by default. MacOS is getting better at this. Windows sucks at it. Where is snaps on that spectrum?

Are you alluding to possibility of an update containing malicious code? Is that because the update's authenticiry is in question or is that because of original developer went rogue? Leaving the system unupdated is insecure. I do not see how auto-updates make it insecure, but themselves.

I depends on what we're updating. ATM I suppose I generally trust a core OS feature's devs to be trustworthy. On the other hand I don't trust random app that was trustworthy to stay trustworthy. Maybe they decided to add an analytics library or maybe it's a game and the decided to add an anti-cheat kit, both of which are essentially root kits spying on me. Maybe one of the libraries they use decided it would be good to do something similar so the app devs are trustworthy but the library devs are not.

I find it strange that we trust as much as we do on our computers. Would you let 1000 people walk through your house unsupervised and unannounced? Would you expect everything to be ok after? Yet so many apps are created either directly or more likely indirectly via its dependencies by 1000s of people. Each one of those people has to be trusted. That's insane IMO. And as we get more and more connected the incentives to do evil rise.

From say 1993 to 2010 I mostly didn't care that Windows wasn't sandboxed. Now every app I download is trying to spy on everything I do either for marketing directly or for analytics which is then shared with "business partners" who then share it with others.

I wouldn't have to worry as much a random library is going to do something bad if it wasn't possible for it to do something bad

https://www.google.com/search?q=malicious+libraries

Post reply on HN