Krita 4.4.0
krita.org
krita.org
- The Affinity suite
- Corel Painter
and perhaps a few others. They do their job of paying their developers, cultivating artist communities, doing R&D and pricing their products at something reasonable for the average artist.
I use Pixelmator (Pro) on macOS. Flat fee (buy to use), though I use it for basic things.
I actually ended up more heavily switching to Krita though, just because I could install it on machines that weren't "mine" without worrying about the license, and it was enough for my purposes in most cases.
If I need any kinda simpler editing I just use this.
(A pity the Corel Draw license in the bundle is for a -subscription- model license.- ... not a lifetime license.)
Started using it years ago - corel bought it I think, and they did not kill it thank goodness.
It's easy for me, easy for me to teach other complete noobs how to do most things with it, and no subscription for internet required to work.
It's great and free (as in beer) even for commercial use.
Microsoft really needs to do something about the whole SmartScreen mess if even properly signed, popular and trusted open source tools like Krita require such a "how to get around the SmartScreen popup" note in their installation instructions.
The strategy is to introduce the store and slowly make independent distribution more and more onerous, using security as justification. When people complain you can say "just put your app in the store and you won't need to worry about signin/notarisation/etc."
Apple are doing exactly the same thing.
I have never seen a regular computer user not clicking the "Run" button in less time than it takes to read anything in that window. One notable exception I can see is people who've pirated games from gog.com, and want to check that they're unmodified.
Can you please for the love of Zeus make up your mind already? "Installing random software from the Internet - bad! Linux good because package manager!" Microsoft offering a "store" (most software on it is free anyway) and allowing signed installers that won't trigger warnings - also bad!
So which is it? And more importantly, how is this any way worse than the common practise in Linux to install 3rd party software via some variation of "wget -O https://some.totally.trustworthy.website/install | sudo bash" that won't show any warning whatsoever?
TL;DR There totally IS a reason to scare users away from installing random crap from the internet. And that reason is independent from operating systems or companies!
Yes.
> Microsoft offering a "store" (most software on it is free anyway) and allowing signed installers that won't trigger warnings - also bad!
Yes, but ONLY because they require you to create a Microsoft account. If you could use it without the account, then it would be fine.
Edit: I also tend to trust package maintainers for established distro's more than I trust Microsoft's QA. This is just me though so only partially relevant.
> So which is it? And more importantly, how is this any way worse than the common practise in Linux to install 3rd party software via some variation of "wget -O https://some.totally.trustworthy.website/install | sudo bash" that won't show any warning whatsoever?
(Windows Store) is worse than (random.exe)||(wget -O some.stupid.site/something.sh | sudo bash) is worse than (Proper package manager)
Why? Name a technical reason and not ideological BS, please. I've yet to hear a proper argument that isn't just "because Microsoft".
Edit: I trust my capability to moderate the sites I download from more than I trust Microsoft to prevent malware on the store.
"Ideological BS": I don't think wanting to stop account proliferation is "ideological BS" I have a certain number of accounts, I want less. I see no reason to make more.
Ideological BS: I don't trust Microsoft to not do more tracking than I find ethical.
So you are implying that your personal capabilities reflect the majority of users out there? That's a bold assumption!
The Windows Store is meant for a general audience, and the general audience are users that ended up with 10 rows of custom "toolbars" in their browser after a few days of using the internet.
The fact that you trust your own abilities over those of Microsoft (of course without giving a concrete example to justify your mistrust) has nothing to do with millions of non-tech savvy users that would otherwise just download Krita.Totally.Not.Malware.Believe.Us.exe from webshop24.ru, because they clicked on that cute cat image that told them to...
Maybe at one point, but at this point the general audience
A) Just does everything in the browser.
B) Knows enough to do things right
C) Does not yet know enough to do things right, will screw up an install, and learn from experience.
D) Will manage to repeatedly screw things up.
D is a surprisingly small group, and I'd personally rather group C screw up their stuff and learn.
> The fact that you trust your own abilities over those of Microsoft (of course without giving a concrete example to justify your mistrust) has nothing to do with millions of non-tech savvy users that would otherwise just download Krita.Totally.Not.Malware.Believe.Us.exe from webshop24.ru, because they clicked on that cute cat image that told them to...
What's to stop me from creating "K-Dev LLC" and putting "Krita+ Ultimate" on the Microsoft store, of course with my own malicious add-ins?
As far as "Without a concrete example to justify your mistrust". Yes. I do not have a concrete "I installed this from the Microsoft Store and it was malware story". That being said, Microsoft has repeatedly shown themselves to be ineffective at security. To be clear, They have a _massive_ and extremely difficult task in front of them. I just have no reason to expect it to work, and experience suggesting it won't.
Reality check: https://blog.emsisoft.com/en/34822/the-state-of-ransomware-i...
Note that not all these incidents resulted from drive-by-downloads or elaborate hacks:
> Riviera Beach: In June, Riviera Beach, Florida, was hit with ransomware when a police department employee opened a malicious email attachment.
In 2019, people still click every e-mail attachment unchecked, even though e-mail attachments have been a primary vector for attacks for decades at this point.
Putting faith in the abilities of the average user is the first step towards disaster. The average user is not more aware or capable in 2020 than they were in 1995. People still carelessly put random USB drives into their machines, still open dodgy e-mail attachments and still download and execute installers and other executables from random websites.
Some sobering stats for mobile [1]:
> Less than 20% of mobile malware is delivered via a browser — the remainder of the payloads come through an app. (Source: RSA Current State of Cybercrime)
Last but unfortunately not least, unpatched systems are still presenting a completely avoidable attack vector for malware and ransomware, because users (both private and industrial/institutional) fail to update their systems [2].
So no, the harsh reality is that the average user is neither aware, nor capable of "doing things right".
[1] https://phoenixnap.com/blog/ransomware-statistics-facts
[2] https://www.mcafee.com/enterprise/en-us/assets/reports/rp-qu...
That being said, most of my experience is with consumers, not corporate IT. I still believe that consumers should be able to install from any source, and not pressured into using the MS Store. In corporate-land however, of course the user should have restricted rights.
As far as the state of mobile, isn't that supporting my point that moderating app stores is almost impossible unless you curate it yourself?
Edit: +1 for your comment though. It made me sit and think about things for a while, for which I thank you.
You don't need an account to use the Microsoft Store, they nag you about login in, but you can click cancel and the app will still install.
1) Installing software directly from the developer --along with being able to develop yourself-- is not only perfectly fine, it's what makes personal computing great.
2) Package management is an over-engineered and inflexible solution that creates more problems than it solves.
3) Installers aren't as bad as package managers but are still overly complex and cause problems. Applications should be single files or directories that can be moved or copied anywhere you want. Numerous OSs had applications work this way by convention and it is also how AppImage works.
4) Application-level security should be applied by default and at the OS level. Mobile OSs got this (mostly) right.
I do like this. The only thing that concerns me is disk space (which isn't really that big a deal at this point) and things like crypto libraries. With the crypto libraries, what happens when the statically compiled package has an out of date library/how do you recover without having to upgrade every program individually? (This is a serious question, I'm not trying to be rude. I'm sorry if I come off that way.)
Nobody's stopping you from that, not even SmartScreen. The issue is that close to 100% of all malware is installed by users and the critique has been that Microsoft is offering neither sufficient protection nor a safe(r) alternative. SmartScreen and Windows Store - whatever your personal opinion about those might be - are completely optional ways to address this critique.
> 2) Package management is an over-engineered and inflexible solution that creates more problems than it solves.
All major *nix-based operating systems and their distributions seem to disagree with you on that; Most programming languages included.
> 3) Installers aren't as bad as package managers but are still overly complex and cause problems. Applications should be single files or directories that can be moved or copied anywhere you want. Numerous OSs had applications work this way by convention and it is also how AppImage works.
And that solves the security and trust issues how?
> 4) Application-level security should be applied by default and at the OS level. Mobile OSs got this (mostly) right.
Oh yeah, especially mobile OSes where every app wants full access to everything or just won't install/run. Pop-ups are just as bad because now you just train users to simply ignore them.
There is no silver bullet here, and SmartScreen isn't some "evil gatekeeper" that just exists to thwart independent software development. It's just an imperfect tool to address security and trust issues with random software packages downloaded from the internet.
Yes, and I still think I'm right and they are wrong. You're welcome to disagree, but I personally wouldn't hold up the distant 3rd place in desktop computing as evidence against my argument.
> Oh yeah, especially mobile OSes where every app wants full access to everything or just won't install/run.
Like I said, only mostly correct.
> Pop-ups are just as bad because now you just train users to simply ignore them.
Agreed, so don't do popups.
> There is no silver bullet here, and SmartScreen isn't some "evil gatekeeper" that just exists to thwart independent software development. It's just an imperfect tool to address security and trust issues with random software packages downloaded from the internet.
I never said otherwise. I just think we can do better than SmartScreen.
FWIW, Windows also has a package “manager”, although it didn’t manage installed packages last I checked (despite being basically a copy-paste of WinGet IIRC). But I see no reason to hold up what AFAIK is the shrinking 3rd place in computing (behind cloud and mobile) as evidence. Servers and phones install software too.
> But I see no reason to hold up what AFAIK is the shrinking 3rd place in computing (behind cloud and mobile) as evidence. Servers and phones install software too.
Ok, let's look at mobile... which uses self contained applications. Huh. How about server... where things like VMs and Docker are increasingly popular because they allow self-contained services. Hell, even developers use Docker to create self-contained build environments.
Regardless, I don't think what servers do is very applicable to how desktops should work. Mobile is much more applicable because they are personal devices, like desktops, but they are still a distinct entity with different use cases.
If the complaint is "because it doesn't work well enough", the proper solution is to just disable it, which is of course an option. Crying "foul!", however, is neither constructive nor helpful in way.
Are you sure you meant exactly what you wrote?
I mean: The correct thing to do if you have a smoke detector that gives false positives isn't to throw out smoke detectors but to complain to the place that sold it and get a new one that works.
To use your smoke detector analogy: if a smoke detector goes off twice a day and once in the middle of the night every other night, you sure as heck DO throw it out. If only because every false alarm desensitises you to actual alarms and makes your default reaction to just remove the batteries of that thing.
The real issue is that the false alarms don't necessarily come from a faulty detector, but are due to the fact that someone keeps smoking in the house or keeps burning their food all the time and then keeps telling everyone that smoking doesn't affect them negatively, because they only smoke one cigarette every other day so smoking is actually safe for everyone and that the detector is to blame for all the false alarms.
This is not just possible, but relatively easy to solve. Applications can be sandboxed by default. Signing the application or user granting it extra rights can remove some restrictions from the sandbox.
Gatekeeper only warns about unsigned software. It has nothing to do with whether it is in the App Store or not.
The options in System Preferences are:
Allow apps downloaded from:
○ App Store
○ App Store and identified developers
There used to be a third option, ○ Anywhere
but the frog is warmer now.Identified developers = signed
FYI: frogs actually do jump out of water as it gets hotter.
You may be right that this changes in the future, but for now I am correct.
[0] https://developer.apple.com/documentation/macos-release-note...
Disallowing unsigned software altogether would contradict other statements they have made.
That said, I wouldn’t be surprised if it becomes something you can only enable from the command line.
They have clearly stated that Apple Silicon Macs will be open to whatever software you want, but they may well choose to make that more difficult for inexperienced users.
This line seems clear that unsigned code is not allowed, although I don't have a Transition Kit to try it for sure.
While I can't see when the original blog post was submitted, I know this forum post was posted 2 hours ago. Are you sure you would benefit from updating even faster?
EDIT: In any case, you could use the AUR package that points directly to the git repo.
I doubt it.
> My experience with repo/package models suggests it very much would not.
The Nix package manager would. However, I have no idea if their packages are kept up-to-date like that.
My cursory search on the interweb did not yield any promising results on the Arch wiki either. Happy to be corrected, of course.
I usually just "Open with AppImageInstaller" when I download them, it pops up and asks if you want to run once or integrate. When you get a new version you can right-click the old one's shortcut/icon and AppImageInstaller's integration give you a "remove from system" type option.
I use Cura as an AppImage, FreeCAD, Lens (Kubernetes "IDE") Zettlr, and a few others as AppImages. It's really clean and convenient.
It really upsets me when I find tools I want only have snaps, because like any sane person, I kill snapd the second I install an Ubuntu system (Laptops) and I run Manjaro on my desktop so snapd isn't going anywhere near it.
[0] https://krita.org/en/item/first-krita-beta-for-android-and-c...
[1] https://play.google.com/store/apps/details?id=org.krita&hl=e...
Is Krita an alternative to InkScape?
Got it to work but it was one of those Linux things where I don't know what I did to get it to work, but it works now, and the next time I set up a new machine, it will be another few more hours of my life.
But yeah Wacom Intuos + Krita = so much fun.
Really looking for something my kids can get into!
Krita supports vector layers, but it's for simple shapes/text overlays
That's got a tonne of filters.