flâneur — a map of the web's best reading

Flatpak - a security nightmare

flatkill.org · 507 words · saved by 1 readers

UPDATE: Flatkill 2020 - let's have a look what Flatpak developers have done in last 2 years to address these issues (hint: next to nothing). Red Hat's flatpak has been getting a lot of attention lately, it's the self-proclaimed new way of distributing desktop applications on Linux. It's secure they say ... Almost all popular applications on flathub come with filesystem=host, filesystem=home or device=all permissions, that is, write permissions to the user home directory (and more), this effectively means that all it takes to "escape the sandbox" is echo download_and_execute_evil >> ~/.bashrc. That's it. This includes Gimp, VSCode, PyCharm, Octave, Inkscape, Steam, Audacity, VLC, ... To make matters worse, the users are misled to believe the apps run sandboxed. For all these apps flatpak shows a reassuring "sandbox" icon when installing the app (things do not get much better even when installing in the command line - you need to know flatpak internals to understand the warnings). Offici

Explore this link on the map →

saved by