• SteveTech@aussie.zone
          link
          fedilink
          arrow-up
          5
          ·
          10 hours ago

          Well, both the Flathub website and KDE Discover list this, so this seems like a GNOME issue and not a Flatpak issue.

          Flathub:

          Screenshot of Evolution on Flathub

          KDE Discover:

          Screenshot of Evolution on KDE Discover

          • diaphragmwp@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            9 hours ago

            FlatHub website

            Where? I don’t see it here. Can click on the “manifest” but nobody will be reading all of that. Tried Tor Browser to rule out extensions. Maybe it’s actually communicating with the desktop client in some way which I don’t have?

            Also, a backdoor in this particular program can steal your PGP keys. Some clueless guy who added it to GitHub for a tutorial may have some issues if it’s not password protected. It’s in no way like Android where “OpenKeychain” were forced to define a protocol and now reading a key prompts the user.

            Oh, and one of the few dozen local privilege escalations found by AI in the mountains of trash of our great kernel completely negate all of this. It has to be AI because no human nowadays is doing all of that anymore. And enslaving humans to pick out code 24/7 isn’t legal anymore anywhere, ya know.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              3 hours ago

              FlatHub website

              Where? I don’t see it here.

              click the red “medium risk” thing near the install button

              Oh, and one of the few dozen local privilege escalations found by AI in the mountains of trash of our great kernel completely negate all of this. It has to be AI because no human nowadays is doing all of that anymore. And enslaving humans to pick out code 24/7 isn’t legal anymore anywhere, ya know.

              that’s not a problem of flathub, but literally all computers. windows, macos, android is also susceptible to it.

              • diaphragmwp@discuss.tchncs.de
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                2 hours ago

                click the red “medium risk”

                Literally how the fuck was I, or let alone “a simple user”, is supposed to know that? “Intuitive, uncluttered UI” my ass. Also “The software developer has verified their identity, which makes the app more likely to be safe” ??? How Android wannabe (without actually being anything like Android) do they want to be???

                not a problem of flathub

                The problem of flathub is the illusion of safety.

                • WhyJiffie@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  57 minutes ago

                  click the red “medium risk”

                  Literally how the fuck was I, or let alone “a simple user”, is supposed to know that?

                  idk, this is the first time I saw that menu. it’s a pretty visible red at a prominent place on the webpage, so I wouldn’t say it’s hidden

                  The problem of flathub is the illusion of safety.

                  where is the illusion of the safety? where does it say it’s the safest thing ever made?

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      18 hours ago

      Just check the permissions of an app before installing. Bazaar has a gauge for how “safe” an app is based on permissions. If it doesn’t request internet, filesystem access, and other powerful permissions, it’ll be marked as the safest.

      Really it’s the same as docker. It’s secure most of the time, but don’t come crying about getting hacked if you give all your containers access to /dev, host networking, etc

    • Billegh@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      22 hours ago

      Pretty much. Snap is the only one with a semblance of anything appearing to be security, and nearly every container requires you to turn it off to run.

    • Bizzle@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      23 hours ago

      Ha! That sucks. I appreciate that article but now I’m having a little bit of an existential crisis.