Unable to load image

Linux :marseypenguin: being secure :marseycop2: is a common misconception in the security :capyhacker: and privacy :marseypedo: realm :marseyspyglow::!marseyjewoftheorientglow:

https://madaidans-insecurities.github.io/linux.html

GNU+Linux bros :marseypenguin: I don't feel so good :marseydisintegrate::marseyhacker::capyhacker:

!codecels discuss

57
Jump in the discussion.

No email address required.

Flatpak aims to sandbox applications, but its sandboxing is very flawed. It fully trusts the applications and allows them to specify their own policy. This means that security is effectively optional and applications can simply choose not to be sufficiently sandboxed.

This author is an idiot. The purpose of self-specifying boundaries is two-fold:

  • It puts a blast radius around an app being misbehaved or being compromised. This is why Chrome self-sandboxes major parts of its runtime, even though their own engineers wrote the code being sandboxed.

  • OS, vendor, and IT policies can restrict installation based on requiring self-selection of more restrictive policies. This is why Google's add-on systems for Workspace have different criteria depending on what scopes an app self-selects, encouraging self-selection of narrower scopes.

Flatpaks could do the latter better, but the concept is sound.

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.