> First, adding a third-party repository, and then using your distro's GUI package manager to install an app from that repository, is a lot more work for the average user...
There are no "average" Linux users. There's only Linux nerds and people who have had their Linux nerd friends install and maintain Linux for them. The whole "problem" is made up.
> Greatly reducing that work, as Flatpak does, is a bug, not a feature. (See further comments below.)
2525 Year of the Linux Desktop
> Second, third party repositories don't promise that their apps are sandboxed; a binary from a third-party repo has the same privileges as any other binary from the distro. Users aren't being told that the third party apps are "more secure".
I haven't seen Flatpak touted to have a security sandbox, nowhere on their site do I see "security" being even mentioned as a feature. So that accusation is made up as far as I am concerned.
> Really? Then why are there thousands of open source applications in my distro's package manager? (And that's without installing any third party repositories.)
Gee, a thousand FOSS applications, what more could a user want? Have you personally ever tried to ship software for "Linux"? Do you even develop software?
> So setting up the system to require some due diligence seems like a better idea than removing the due diligence just because users will find that easier, and then claiming that you can still provide security.
It's "security by inconvenience". This has nothing to do with real security. These users you are trying to protect don't exist, but even if they did, you wouldn't protect them by making it hard for them to install software, you would be making them use Windows instead.