A letter to Microsoft for not attributing authors of the Edge Flatpak app
theevilskeleton.gitlab.io
theevilskeleton.gitlab.io
<id>com.microsoft.Edge</id>
<name>Microsoft Edge</name>
<developer_name>Microsoft Corporation</developer_name>
You can’t go round claiming to be Microsoft and then add a disclaimer in the notes field that you’re not actually Microsoft, which they do, after four paragraphs of other text:
> NOTE: This wrapper is not verified by, affiliated with, or supported by Microsoft.
I don’t think this is an adequate way to surface such an important piece of information, one which arguably contradicts the package metadata. Flathub needs to figure this out.
The developer_name element is for the developer of the application that is being packaged. It is not the name of the maintainer of the flatpak.
>The <developer_name/> tag is designed to represent the developers or project responsible for development of the project described in the metadata.
https://www.freedesktop.org/software/appstream/docs/chap-Met...
Why is there not at least a packager or maintainer field?
On flathub the developer is the developer of the software being published and the publisher is the people who packaged it.
I am on mobile, so maybe there's more info on desktop? I see nothing indicating if this is official or not, other than a note at the bottom of the flathub description telling me it is not official, which seems strange for that to be the only place indicating that.
> Needless to say, this most likely an oversight so I have not concluded that this was intentional, yet
I don't see a point of disagreement. Developer != flatpak maintainer. Putting themselves there would rightly have them called out for misappropriation.
I've been adopting flatpaks a fair bit lately but something doesn't sit right that there's not an obvious way (At least in most front ends) to know:
1) Who the packager is.
2) Is the flatpak officially sanctioned by the developer of the software?
2.5) If not, how do I know that it was packaged correctly? Was the build from a clean source?
3) Is it really the latest version? (or is the potential non-official packager perhaps lagging behind the official release)
Perhaps you can dig further into GitHub and get the information, but it's not blatantly obvious at a glance.
However, flatpak is only mentioned twice, both as "run this command" in step 4 - hardly a "We at microsoft wrote this and you should use it" type of "promotion".
As someone who uses very little Microsoft and doesn't use Steam, I don't even know what "Edge flatpak" is, nor even what the flatpak command does or is.
I don't think there's going to be much "outrage" to be generated here.
> “We worked closely with Valve and the Xbox Cloud Gaming team to bring support for Xbox Cloud Gaming (Beta) with Xbox Game Pass Ultimate through Microsoft Edge Beta for the Steam Deck,” says Missy Quarry, a community manager for Microsoft Edge.
Then there is a tweet which links to this reddit post. That reddit post has you install the Microsoft Edge flatpak. If you search using DDG or Google for "edge runs on steam deck", you will see that there are multiple news articles reporting on how Microsoft has worked with Valve to get Edge running on the Steam Deck. All of these use the flatpak mentioned in the post. I can absolutely see why the author of the flatpak would want at least some attribution instead of Microsoft announcing that they alone have gotten Edge running on the deck.
Also, it is worth it to read the Wikipedia page on flatpak if you don't understand what flatpak is. It is a really important technology if you want to understand why the author is mad.
[1] : https://www.reddit.com/r/MicrosoftEdge/comments/th77w9/micro...
[2] : https://www.reddit.com/r/MicrosoftEdge/comments/th77w9/micro...
Even if there were, it would have to rely on either the Flatpak Chromium's downstream patches or Zypak anyway (unless they used --no-sandbox, which would be awful).
The Edge flatpak is essentially a package.
But I also don’t see why this article would or should specifically mention who had happened to package the app.
If anything, I would say that it would be more reasonable to instead ask Valve to highlight who is packaging stuff. Valve is responsible for the representation of things on SteamOS, not Microsoft.
Asking for credit for packaging in a random support article seems.. strange?
I mentioned this to the article author, and they edited the post to include the Reddit announcement.
Flatpak is really special technology. Joy to package, excellent end user experience, and completely open.
Because that model worked so well for iOS and Android?
I think it worked out pretty well tbh. Would be an odd choice not to copy the model.
(These aren't the only other points, just ones off the top of my head)
When installing software using any other packaging system you have no isolation what so ever. The software is able to help to do anything on the system as root (because the installer script runs as root). Not even Nix, which is supposed to give you some kind of reproducibility helps.
I personally don't trust every single software developer with the integrity of my entire computing environment. I want the code I run to be isolated and only be able to access the things they are supposed to be able to access.
Now, there are valid concerns that Flatpak doesn't provide enough isolation, and that it's never really clear what rights a given package actually has, forcing you to use Flatseal to manually configure the rights for packages. However, no other packaging system does anything to address the terrible security situation on Linux, so there is really no other alternative.
Well, there is one alternative which I generally recommend people to use which is Qubes OS, but it takes quite a bit of discipline to use it correctly, so it's not practical for all users.
Once most software is installed it will run unprivileged, and in most cases will be even further restricted by selinux, app armour, and/or systemd.
You're right that apparmour can help, but getting good profiles for the software you use is not easy, and I'd say less available than Flatpak.
Is it anything more than a false pretense at security? Having a "sandbox" which most apps don't use ( usually for good reason), and not giving the users an easy way to check if the app they're installing uses the sandbox.. what's the point of that sandbox then? It's just security theater.
I (nor anyone else that I've seen supporting Flatpak) has ever claimed it's a perfect solution. If you want something closer to being perfect, you need to use Qubes OS. However, no other solution even seem to try to provide a solution for isolation on Linux.
If I want to run a program without habing to trust it with access to my $HOME/.ssh directory, what is my alternative?
Do I actually need to list all of them? There are a lot.
Given that there's no mutual exclusivity to running flatpaks and running distro based software I don't see why there's a need to stick to anything. You're not losing anything by also adopting flatpaks. Do you also not compile your own software as to not incur the wrath of the package maintainers?
It's Linux, you can install software however you want
Distros can and do have their own flatpak repositories, notably Fedora and elementaryOS.
There are also third party apt repositories, maintained by someone other than a distro.
In this respect, apt and flatpak work exactly the same way.
Are we even using the same software? That has not been my experience at all.
Stuff that was natively designed for flatpak was flawless while other stuff had some minor issues when it expects things like direct file system access or expects libraries to just exists on the fs rather than explicitly bundling them in or requesting them.
I don't even see the problem, a help article says to install a browser? If I blog about how to install software, I have to give attribution to whomever packaged it?
This is just absurd.
It's also not really "pushed" onto Flatpak: significant parts of the ecosystem already use the scheme, so Flatpak following along allows an app to keep the same name across multiple different places (desktop file, D-Bus name, etc).
Either it's a cultural issue, or that the management are sorry they got caught. I'm thinking this is more of the second option.
What's wrong with Edge?
Even without such Microsoft-introduced crap, the better question is what's good about Edge? Why use it over any other Chromium-based browser or Firefox? At the moment there's exactly one good reason - if you have a Steam Deck and want cloud gaming, because it's the only browser that supports it.