Why would you give those apps root access?
Why would you give those apps root access?
Easy to get root anyway, just add an alias to sudo to .bashrc and whenever the user follows an online instruction guide into fixing something they'll get root privileges.
or overwrite LD_PRELOAD for the user
or replace the users desktop files and pretend to be another application (because you can overwrite /usr/share/applications launchers in .local/share/applications)
Not that it makes a huge difference in practice, IMO. The apps most users run (i.e. distro apps) are plenty trusty for normal threat models. Apps that run real untrusted code (web browser) have their own sandboxes. And people with more serious threat models can run qubes or tails or whatever
You shouldn't but you install debs/rpms from the internet which get root permissions during install.
As in, any unrestricted process with user privileges on Linux can up to root through vulnerabilities in the kernel or other components. Namespaces, LSMs, and seccomp limit that exposure.
> unrestricted process with user privileges on Linux can up to root through vulnerabilities in the kernel or other components
Getting pwnd via vulnerabilities is very different from giving root access. You're arguing with a strawman, I'd rather not engage.