• nitrolife@rekabu.ru
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    It’s not the 80s, and I can save a few megabytes to keep my system running smoothly and well-managed.

    And then it turns out that you have 18 libssl libraries in diffirent fpatpacks, and half of them contain a critical vulnerability that any website on the Internet can use to hack your PC. How much do you trust the limitations of flatpack apps? are you sure that a random hacker won’t hack your OBS web plugin and encrypt your entire fpatpack partition (which some “very smart” distributions even stuff office into, and your work files will be hidden there). People have come up with external dependencies for a reason.

    • Allero@lemmy.today
      link
      fedilink
      arrow-up
      0
      ·
      19 days ago

      Fair criticism!

      However, the extent of the damage is limited by flatpak and whatever permissions you have set, and, if I understand it correctly, you cannot attack one flatpak through the other unless they share access to some files.

      Also, I haven’t seen this kind of attack in the wild (maybe I’m not informed enough?) as opposed to rogue maintainers injecting malware into packages.

      On an unrelated note: apparently, there is finally some Russian Lemmy instance? That’s a welcome change.