You might find this shocking, but in many parts of the world "nice computers on fast internet" is kind of a given now. So for those, even if it is "gigabytes", it is worth it for the various benefits like security or convenience, for example.
You might find this shocking, but in many parts of the world "nice computers on fast internet" is kind of a given now. So for those, even if it is "gigabytes", it is worth it for the various benefits like security or convenience, for example.
None and no one said that it does offer any kind of security. The criticism was entirely unrelated to that.
On the other hand, flatpaks sandboxing is also severly limited by the fact that most packages do not make use of it much. In the past the runtimes offered by flatpak were also lacking behind on critical security updates [0]. Did that change in the meantime?
Edit: They removed many of their examples at some point, so it's no longer as bad of an article.
For example if VSCode wouldn't have direct access to the file system, it would be unuseable since it doesn't support portals to ask the user to grant it access to specific folders (by selecting them through the file picker).
In the process of packaging an app for flathub, the packager has to provide some reason for why for example full file system access is necessary. The discussion to add or remove permissions are always open [2].
[1] https://theevilskeleton.gitlab.io/2021/02/11/response-to-fla...
I've never had an AppImage hacked.. (or honestly anything else hacked on a Linux machine) though I'm not running AppImage servers
> in many parts of the world "nice computers on fast internet" is kind of a given now
Well if they want to be an appstore solution for the Linux ecosystem then they need to cater to everyone, not just rich kids in silicon valley
A calculator should be run as a fully isolated application, with no filesystem access and no ability to damage anything even if it tries.
I could upload a "Calculator" application that looks harmless, and even functions as a calculator, but actually steals your GPG keys and logs keyboard input. With a sandbox this would not be possible (in theory).
A "calculator" app isn't really unique here, it can be malicious just as well as anything else could be.
You do not want "apps" to be able to do this at all!
A calculator shouldn't really have access to many things anyways, ideally only access to things it requires to function.
I have a few apps installed via Flatpak there are multi-gigabyte updates several times a week, usually for the base images under the apps themselves. I apparently have 3 different copies of GNOME, more than half a dozen platform images, and several copies of the Freedesktop SDK.
Many Flatpaks aren't sandboxed, either.
It shouldn't. Security should be implemented as a separate tool, not tied to any package management system.