Live data from Hacker News

Flatpak – a security nightmare – 2 years later (2020)

flatkill.org

201–210 of 296 posts

Re: Flatpak – a security nightmare – 2 years later (2020)

#201

Earlier quoted context omitted.

No, I think what got us into this mess is Ubuntu being a server distro with a standard release cycle (as opposed to rolling release) getting incredibly popular on desktops. Desktop users want the newest version of their UI apps and don't care so much about stability. Ideally, the developers of e.g. Inkscape would offer the newest version on each Ubuntu version via apt, but that does not seem to be feasible. I am no A…

> Desktop users want the newest version of their UI apps and don't care so much about stability. [Citation needed]. Can you imagine telling this to someone who is about to present on a conference call, but zoom updated automatically and fails to start now?

If you define "care" as in, "random updates cause enough instability that they make alternate OS's favorable for accomplishing the same tasks," I'd cite Windows autoupdate as fairly hard evidence that people don't care.

I imagine MS has crunched the numbers at some point, and decided that the amount of lost work and interruptions due to forcible updates (especially contrasted with the benefits of updates) is not causing a significant number of people to ditch their OS for a competitor.

Re: Flatpak – a security nightmare – 2 years later (2020)

#202
post #197
post #178

Earlier quoted context omitted.

I mean what do you want to have happen? ptrace every application, stop on every openAt(2) call and pop up a permissions dialog? macOS can get away with solutions like this because they control the kernel and userspace but on Linux it’s a much tougher problem.

TBF you could put support into the two common GUI toolkits, to defer to a Flatpak portal.

But that’s exactly what GTK and QT have! It’s what to do with apps that don’t use some abstraction that supports portals that’s the issue.

Re: Flatpak – a security nightmare – 2 years later (2020)

#203
One thing that gets me about the sandbox of flatpak is that it doesn't seem to be up to the user. If the developer of the app chooses the permissions, then there isn't a fundamental difference for security from having all permissions anyways.

Ideally a user installs the app and they would know, without reading anything else about the app, that the app is separate from their system. If any app you install is NOT separate from the system, then... the sandbox is like making a giant wall but having a door right in the middle of it.

Re: Flatpak – a security nightmare – 2 years later (2020)

#204
post #201

Earlier quoted context omitted.

> Desktop users want the newest version of their UI apps and don't care so much about stability. [Citation needed]. Can you imagine telling this to someone who is about to present on a conference call, but zoom updated automatically and fails to start now?

If you define "care" as in, "random updates cause enough instability that they make alternate OS's favorable for accomplishing the same tasks," I'd cite Windows autoupdate as fairly hard evidence that people don't care. I imagine MS has crunched the numbers at some point, and decided that the amount of lost work and interruptions due to forcible updates (especially contrasted with the benefits of updates) is not caus…

Competitor? Windows is still >85% of desktop use or thereabouts - you can buy an expensive mac or you can go to hell and try out linux; neither is really an alternative for many so they just accept what happens.

Re: Flatpak – a security nightmare – 2 years later (2020)

#205
post #48
post #16

Earlier quoted context omitted.

I don't agree with your assessment at all. The linked article seems to mostly agree with the criticism levied, but disagrees mainly with the severity and degree of the issues. For example, OP says: > Almost all popular applications on flathub come with filesystem=host, filesystem=home or device=all permissions The response says that no, not "almost all"; out of the 50 surveyed apps, 23 of them had excessive permissio…

Snap and flatpak: they suffer from identical problems (in the snap world, these are "classic" snaps which get almost no restrictions). Any app that needs to save files in your home directory, which all the traditional apps do (Gimp, Inkscape, *Office...), has to have r/w access to your home directory (duh). So I would venture to say that this is all misleading marketing, which is mostly what the OP complains about to…

Of course, in "classic" apps, there is explicitly no protection. They don't promise it, and you don't get those by default when trying to install a snap.

Re: Flatpak – a security nightmare – 2 years later (2020)

#206

Earlier quoted context omitted.

Why not just fake stuff? If you give software no file permissions, show it an empty dir. Tell the software you saved it's file but don't, just keep it in an memory overlay just for that program's run. If it wanted the network, give it a dummy net.

And then have a barrage of users complaining that their app packaged in flatpak doesn't work.

Users are stupid, but they are not as stupid to press no on a request to allow an application to open files and then complain that no files exist.

Re: Flatpak – a security nightmare – 2 years later (2020)

#207
post #48

Earlier quoted context omitted.

Snap and flatpak: they suffer from identical problems (in the snap world, these are "classic" snaps which get almost no restrictions). Any app that needs to save files in your home directory, which all the traditional apps do (Gimp, Inkscape, *Office...), has to have r/w access to your home directory (duh). So I would venture to say that this is all misleading marketing, which is mostly what the OP complains about to…

A capability model fixes this: the application launches a file chooser which it does not control , which can then return it an fd or other token giving the application the capability to read from or write to a specific file. Of course, this would be a considerable effort. But it's probably where we're going.

I've long argued for applications to use file choosers they do not control, but not for security reasons. I've wanted it for UI reasons.

Somewhere I've got a screenshot of a Linux system I had with half a dozen applications trying to open a file. Each used a different GUI framework or widget toolkit, each of which had its own file dialogs, and so the user gets presented with half a dozen different file choosing UIs. It was completely ridiculous.

Making the UI suck less was not a good enough reason to get any of the major GUI frameworks to support separating file choosing from apps. Maybe improving security will be a good enough reason.

Re: Flatpak – a security nightmare – 2 years later (2020)

#208

Earlier quoted context omitted.

From my perspective as a Flatpak user I can say I hate how the current file access restrictions are implemented, it's confusing and annoying. I use a messenger installed via Flatpak. So whenever I receive a file in it I cannot save it anywhere outside my Downloads folder. So every single time I then have to open a file manager and manually move the file somewhere else. Similar for the other way around - I have to cop…

If that can make you feel better, it is exactly as annoying for mac os apps on the mac app store. I don't know anyone using Mac professionally (for e.g. design, etc...) who uses AppStore apps because of that

If you need excess permissions, then why use a package format that promises sandboxing?

Re: Flatpak – a security nightmare – 2 years later (2020)

#209

it doesn't matter what people think both snap/flap user experience is trash linux desktop is doomed to fail people the people who make decisions are clueless and tasteless

> linux desktop is doomed to fail

What does this even mean? I’ve been using Arch Linux with KDE as my only desktop OS for years and it’s a wonderful time. If you think Windows is better and prefer to use that, great. I personally prefer Linux and a lot of other people do as well.

Re: Flatpak – a security nightmare – 2 years later (2020)

#210

it doesn't matter what people think both snap/flap user experience is trash linux desktop is doomed to fail people the people who make decisions are clueless and tasteless

linux desktop is never going to take off and died off when all the money moved to the cloud - it's not the 2000s, you can download windows and run it for free because that's not where the money is anymore. For the average user that's not technically oriented, that's going to be their goto solution.

> linux desktop is never going to take off

Who cares? Why is popularity so important to you?

Post reply on HN