Ubuntu 16.04's new Snap format is a security risk
zdnet.com
zdnet.com
You can get mouse events besides keystroke events, grab windows including the root window (screenshots), you can send keystrokes to other applications.
tl;dr assume no isolation between any X11 applications. Typing in your credentials in some terminal? You should trust all other X11 applications that are currently running, including the browser that runs untrusted programs all the time.
(There is a workaround: start applications in separate Xephyr sessions.)
> The security mechanisms in snap packages allow us to open up the platform for much faster iteration across all of our flavours as snap applications are isolated from the rest of the system. Users can install a snap without having to worry whether it will have an impact on their other apps or their system. Similarly, developers have a much better handle on the update cycle as they can decide to bundle specific versions of a library with their app. Transactional updates make deployments of snap packages more robust and reliable.
> By bringing snap packages to Ubuntu 16.04 LTS we are unifying the experience for Ubuntu developers, whether they are creating software for PC, Server, Mobile, and IoT Devices. Snapcraft, a tool available for snap development, makes it easy for developers to package their apps and dependencies. Developers targeting snap packages get a great environment to write and test their applications – directly on their desktop, rather than being forced to use a device or a virtual machine.
I think it is just a poorly worded announcement that implied security isolation on Ubuntu 16.04 LTS when that was not the intention.
Similarly, they are just as secure as apt so there is no loss of security so the claim of the OP's title is misleading.
Some more details about snap interfaces:
So if you want to lob accusations of inaccurate or misleading claims, better to aim them at Canonical, who are pitching this as a security panacea when it's anything but.
But X11 was there before and installing random packages on your Desktop (or piping stuff from curl to a root bash, etc) is not secure. That is not controversial, I'd think.
> Matthew Garrett, a [...] security developer at CoreOS.
There might be a slight conflict of interest here. Although I am all for exposing security threats and issues regardless, Ubuntu has been advertising LXD, Juju and such technologies which somewhat compete with CoreOS, so I can understand why they'd want to move quickly to discredit it.
The whole adorable teddy bear thing is a bit childish perhaps. "Oh look how evil the new Ubuntu is, it lets evil teddy bears eat your data".
The point that canonical is trying to push that installing random packages is more secure with snap/snappy because they are sandboxed (to some extend). However, as Matthew Garrett points out, this sandboxing is practically useless as long as you are running on X11, since a sandboxed program can send keystrokes to other applications, grab keystrokes, do window grabs, etc. So it still has as much control as unsandboxed applications as long as they are running in a normal X11 session.
He is right to call them out on this.
There might be a slight conflict of interest here.
Since he is actually stating (known) facts about X11's security model, I don't see the problem.
In a press release. Yes it is more secure but when running on a desktop with X11 will have same issues as before with X11.
Imagine a press release for 16.04 that all of the sudden starts going into details about X11 vulnerabilities. Who does that?
I am can see refuting a white-paper where Ubuntu makes detailed claims about security guarantees under certain threat models but this seems like a cheap shot to me.
Moreover under this model you can shoot down any product. "Tor provides privacy" -- "Ah no it doesn't, here are more details". "The new JDK is faster than the old" -- "Wrong! Here is a benchmark where it shows it is slower". And so on.
Yes, it's sold as being more secure than other solutions, when it in-fact isn't, but the headline still is clickbait because if Snap is a security risk then everything else is too.
It's entirely possible for SNAP to be 'more secure than other solutions' while still exposing users to one specific risk. There's no need for perfection in order to be able to rightly claim 'more secure'.
TL;DR: I don't want to end up with an iOS on my desktop.
However I understand that sometimes, in ways I can't figure now, I could want to run programs in a jail. Maybe games? The music player? Skype?
But the big security risk IMHO is that vulnerable libraries are not updated into every single snap I have. The unmaintained app will break the security of all the system.
A not pleasant consequence of snaps is that we'll have to download upgrades for every single snap whenever a popular .so gets updated. It's going to be hundreds of MB instead of a few kB. This on top of the extra space required by all those jailed apps. I better have to hurry up and buy a very large SSD.
These days, if you want to do your thing with your Linux install there are perhaps two big names. Gentoo and Slackware. Beyond that you get a smattering of smaller distros on shoestring maintenance.
Sadly much of the upstream is under control of previously mentioned big boys, and they seem to have a crusade going where only their approach matters.
The security mechanisms in snap packages allow for much faster iteration [across all versions of Ubuntu] and Ubuntu derivatives, as [snap applications are isolated from the rest of the system].
Source: https://insights.ubuntu.com/2016/04/20/canonical-unveils-6th...
Canonical is selling snake oil here when it comes to the desktop. snap applications are not isolated, because they still have full access to any other X11 application due to X11s security model. Garret is right on calling them out on this.
Compare this e.g. to OS X where there is both sandboxing (as in the application cannot touch other parts of the filesystem, unless you explicitly allow it to) and GUI isolation (applications cannot read events sent to other applications, unless it's an accessibility application and explicitly enabled by the user).
I don't know enough about either platform to respond to your OSX comparison. But if the concern is that they don't isolate enough then you are entitled to that opinion. But overall this is an improvement in this regard (whether or not its an improvement to the overall package management system is open to interpretation).