Live data from Hacker News

Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

jatan.blog

391–400 of 645 posts

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#391

> Snap applications auto-update and that’s fine if Ubuntu wants to keep systems secure. But it can’t even be turned off manually. OMG. Is this real? This is the exact reason I use Linux instead of Windows 10 or macOS. I am not a grandma who can't stay up to date on tech news. At the least there should be a toggle for power users. But no, you can only defer it. Am I the only one who doesn't like it when your already s…

+1 Insightful. > GNOME Calculator was put on the ISO as a snap to help us test the whole “seeding snaps” process, not because it was a fast-moving, CVE-prone applications. Chromium, Firefox and LibreOffice fall more into that category. Ok so the whole snap thing comes down to updating browsers. Is this for real? I want the web, not the browser to change daily, or to consume more bandwidth than my www usage :)

The browser is actually the number one component you should update as soon as a security fix comes out. If you don't want new features ("more free stuff!"), use an LTS version that only includes the security updates?

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#393

So I run Kubuntu on my work laptop (X1 Carbon) and just upgraded to 20.04 last weekend. I had a vague idea there were different competing standards for "linux apps that work across distribution" but didn't know people had such a problem with snap. It just seemed like a useful tool for installing proprietary stuff that wouldn't normally be packaged by the distribution. I just checked and the snaps I have that aren't f…

> Is snap somehow user-hostile? Yes, but more importantly it's insecure. The ease of typo-squatting is a real problem.

Isn't using the internet insecure then? I can typo bankname.example.nl as well.

Not that I don't see your point: a curated list like the repositories is preferable to a system where anyone can claim any name, but I am not sure that this extrapolates to the statement that "it's insecure" as a whole.

Out of interest (I don't use Ubuntu/snaps myself), is that really the case? Can I actually a publish without any checks and, once I got half a million users by repackaging the deb file in snap, add some subtle malware? There is no review process or anything?

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#394

Earlier quoted context omitted.

45 to 90 mins to update my Macs. They might not reboot 5 to 10 times but it's not quick. 19.04 Ubuntu just died on me today (I know some expert could have gotten in working). Apparently 19.04 support ended and someone took down the servers. So trying to update would tell me something about the servers having no release file. And they wouldn't let me update to 20.04 until I patched 19.04. I never modded anything. What…

I don't know why major distribution upgrades are so unreliable. I used to be a Fedora user and it was pretty much impossible to upgrade the distribution version without breaking a lot of stuff. The package manager corrupted its own database once. I switched to Arch Linux and never had these problems ever again despite all the memes about Arch being unstable.

Distro upgrades have been pretty much solved problem in Fedora since about Fedora 20. With Fedora 32 just released, that means ~6 years ago.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#396

Maybe I'm in the minority but I like Snaps. I wish all software would auto-update silently in the background -- when's the last time you even thought about upgrading Chrome? The author of this article claims it's too difficult to find Flatpak apps and that the Ubuntu software center prioritizes Snaps over .deb. Are platforms never allowed to migrate to a new standard? Why is it Canonical's fault that authors of indiv…

> when's the last time you even thought about upgrading Chrome?

But that's exactly what apt does. I last thought about updating Firefox (to use a more fitting example in the context of FOSS) around the same time as I thought about updating GIMP: not that I can remember.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#397

Maybe I'm in the minority but I like Snaps. I wish all software would auto-update silently in the background -- when's the last time you even thought about upgrading Chrome? The author of this article claims it's too difficult to find Flatpak apps and that the Ubuntu software center prioritizes Snaps over .deb. Are platforms never allowed to migrate to a new standard? Why is it Canonical's fault that authors of indiv…

> when's the last time you even thought about upgrading Chrome?

On Linux, Chrome does not autoupdate as it does on Windows or Mac. It installs apt or yum repository and then it is updated together with other packages, when YOU run the update using apt/yum/dnf/whatever frontend you use.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#398

Maybe I'm in the minority but I like Snaps. I wish all software would auto-update silently in the background -- when's the last time you even thought about upgrading Chrome? The author of this article claims it's too difficult to find Flatpak apps and that the Ubuntu software center prioritizes Snaps over .deb. Are platforms never allowed to migrate to a new standard? Why is it Canonical's fault that authors of indiv…

You claim that snap offers real benefits but list none and dismiss detractors as irrational and suggest that instead of complaining about Snap users who have no desire to use snap should invest their own efforts to improve something they have no desire to use instead of being critical.

You are correct that this appears to be EXACTLY like the systemd debate.

Snap HOPES to provide an easier environment for developers to target and thus provide a richer ecosystem for users to enjoy. This like trickle down economics probably isn't real. Like literally every other time Canonical decided to go their own way they will provide an inferior option that isn't taken up outside their own ecosystem before eventually giving up and joining the crowd. Unless it attracts highly hypothetical new developers to linux it offers nothing but downsides to users.

- It's tied to a close source server run by and solely controlled by Canonical with no ability to add software channels like virtually every other major software distribution model for Linux. This means not only could Canonical exercise undue control over how their users use software on their platform it means others including repressive governments could force it to on their behalf.

- Users may only install the most recent version of software and will be updated to the most recent as soon as it comes out. -- This means that if devs push a buggy version you are stuck with it until its fixed. If it isn't fixed for months you just can't use the software. Bugs that effect everyone will probably get fixed immediately. Bugs that effect niche features or a smaller number of users are liable to go unfixed for longer. Please see bugs that are open for years at a time.

-- In case of developer getting compromised ability to push updates to all users as soon as users machine is online means that a substantial portion of user base can be hit within minutes and almost all within hours. If a new version had to get pulled in and then distributed at irregular intervals a new version would take at least weeks to compromise most users. This would give users/packagers/distros/developers time to realize what is going on before all users are effected.

- For some reason they are slow to start

- Waste users bandwidth and storage even with one or the other is dear.

- Results in 17 different apps having 17 different version of a dep 16 of which have known security vulnerabilities because apps don't use system libraries that get updates.

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#399

Earlier quoted context omitted.

So because perhaps some '"power users" can't be trusted" (in your opinion), that makes it's okay to just take away their own control of their own computers? (That kinda reminds me of "trust us, we're the government and we know what's best for you".) Sorry, but that goes against everything that this whole "free software" thing stands for.

>> (That kinda reminds me of "trust us, we're the government and we know what's best for you".) Or, why we have regulations to protect workers. Everyone doesn't have to share your worldview. There are plenty of reasons why these changes are happening. The people making the changes are normally aware of their trade-offs. Change is the key word. If the world was better before from the perspective of the designer then t…

> If the world was better before from the perspective of the designer then they are unlikely to have changed anything

you vastly underestimate the amount of changes which are just done because people have to justify doing things in order to get a paycheck

Re: Ubuntu 20.04 LTS’ snap obsession has snapped me off of it

#400
post #22

We tried to make an internal IoT device using Ubuntu Core and snaps because the capabilities of it were very promising. We started a PoC and about halfway through we hit a major roadblock. Our enterprise network does certificate substitution, and Ubuntu Core absolutely does not allow you to install your own certificates globally, so our devices would never receive updates. We tried EVERY hack we could think up, short…

> We tried EVERY hack we could think up

Just to be sure, installing the CA from that MITM box didn't work? Because that should be the generally recommended solution and I can't see why snap would have a hardcoded CA list separate from the system. If that didn't work, it's indeed a bug, but a rather weird one; definitely worth posting to the bug tracker.

Post reply on HN