Flatpak – a security nightmare
flatkill.org
Flatpak – a security nightmare
1–10 of 264 posts
Re: Flatpak – a security nightmare
#2Re: Flatpak – a security nightmare
#3beyond disappointing that RH would release such a thing.
Re: Flatpak – a security nightmare
#4Re: Flatpak – a security nightmare
#5Re: Flatpak – a security nightmare
#6Sheesh, while the issues raised are all valid, this does not actually justify such a conclusion about the intent of the Red Hat developers. Telling people what their side of the story is for them in a dismissive fashion like this is not going to make it more likely that they admit their mistakes.
A bit of Hanlon's Razor[0] goes a long way to resolve problems involving human cooperation (of any kind) more smoothly.
Re: Flatpak – a security nightmare
#7Wait a minute, did somebody get so pissed at flatpak that they bought a domain name just to specifically host that single blog post?
Re: Flatpak – a security nightmare
#8Is the sandboxing of flatpak more or less secure than docker?
Re: Flatpak – a security nightmare
#9Is the sandboxing of flatpak more or less secure than docker?
It sounds like the bigger issue isn't that the underlying technologies are fundamentally better or worse, but that the de facto configurations are worse. In particular, the median docker container can not write to my home directory. The median flatpak can.
Despite the ordering, the "no updates" seems like a way worse issue than the "most of the sandboxing is ineffective". It seems pretty clear to me that a lot of apps need wide access and the first person who does a great job at that will do us all a big security favor but we're not there yet in terms of UX. Sometimes I really want my text editor to edit my bashrc. Maybe that should require a privilege escalation, that's fine.
Re: Flatpak – a security nightmare
#10Is the sandboxing of flatpak more or less secure than docker?
Which is to say, when you hand out the privileges laid out in the article, it really doesn't matter what software you used to whitelist "every thing".