Spectacle8011, (edited ) to linux in If only more Linux programs followed sandboxing best practices...
@Spectacle8011@lemmy.comfysnug.space avatar

I don’t doubt it, but this is a good place to start.

This claim has interesting phrasing:

Adding X11 sandboxing via a nested X11 server, such as Xpra, would not be difficult, but Flatpak developers refuse to acknowledge this and continue to claim, “X11 is impossible to secure”.

If you look at the GNOME post, you’ll see they haven’t argued against including a nested X server at all:

Now that the basics are working it’s time to start looking at how to create a real sandbox. This is going to require a lot of changes to the Linux stack. For instance, we have to use Wayland instead of X11, because X11 is impossible to secure.

I’m not saying they haven’t refused to acknowledge this elsewhere, but it’s strange to point to this blog post which acknowledges that the sandbox is very much a work-in-progress and agrees with Madaidan that X11 is hard to secure.

Does Xpra provide better sandboxing than XWayland? If not, I think the Flatpak developer’s solution to this is: just use Wayland. And obviously, there’s plenty of room to improve with the permissions Flatpak does offer.

I did some searching on the Flatpak Github for issues and found that you can actually use Xpra with Flatpak, and the answer is “just use Wayland”:


This is also concerning:

As odd as this may sound, you should not enable (blind) unattended updates of Flatpak packages. If you or a Flatpak frontend (app store) simply executes flatpak update -y, Flatpaks will be automatically granted any new permissions declared upstream without notifying you. Using automatic update with GNOME Software is fine, as it does not automatically update Flatpaks with permission changes and notifies the user instead.

Source: privsec.dev/posts/linux/desktop-linux-hardening/#…

It’s great that GNOME Software notifies you when permissions change! I don’t use Flatpak enough to know, but I hope flatpak update notifies you too if you don’t use the -y option.

governa, to random
@governa@fosstodon.org avatar
aires, to obsidianmd
@aires@tiggi.es avatar

@obsidianmd Make sure you all update Obsidian to 1.4.13. It fixes a critical bug.

users - the update just came through for me, so you should be able to run flatpak update to get it.

topher, to random
@topher@mastodon.online avatar

Curious which distro repos end up with patched builds first

topher,
@topher@mastodon.online avatar

Official obviously takes the lead - already there.

Not yet on 38 repos

Nothing yet or LMDE

Users of other Linux distros feel free to chime in with updates. I'm about to check and (edit: Rocky and the RHEL family appear to use the extended support release like Debian; Manjaro currently has 117.0-1 in stable)

Anyone with who uses snap?

thelinuxEXP, to random
@thelinuxEXP@mastodon.social avatar

Since there are a bunch of misconceptions around Flatpak, I decided to make a guide to dispel these, and explain how to do a few things, like theming all applications, using the command line interface to manage them, installing them from your web browser, and more:

https://youtu.be/IYXlgzrZRIE

omglinux, to random
@omglinux@mastodon.social avatar

Flatsweep Cleans Leftover Data from Uninstalled Flatpaks https://www.omglinux.com/flatsweep-flatpak-cleaner-app/

Welchen Browser nutzt ihr? German

Ich habe schon viele Browser durch und viele haben ihre Vor- und Nachteile. Zur Zeit benutze ich Edge mit dem verbesserten Bing, weil ich ChatGPT4 + Internetanbindung testen wollte ohne 20 Dollar im Monat für einen kleinen Spaß auszugeben. Mittlerweile hat Microsoft die KI auch hart gestutzt. Zumindest kommt es mir so vor....

trex, to de_edv in Welchen Browser nutzt ihr?

@ulfi @Tionisla @b0tch Paketmanager zu mischen macht nur Ärger und macht das System instabiler, musste ich leider selber erfahren. Ich lasse daher die Finger von und .

sonny, to random
@sonny@floss.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines