Skip Navigation

Posts
15
Comments
91
Joined
3 yr. ago

  • Yeah as they said it’s complicated, but in an unintuitive way more sandbox of apps can lead to apps being less effective at sandboxing themselves. Which, like you said, can be good bad or neutral depending on your threat model.

    Personally I am leaning towards not using browser in Flatpaks since I trust the browser to sandbox itself. Not the position I started from initially where I would have assumed more sandboxing is a uniformly good thing.

  • You should probably read the included details if you haven’t and address those points directly. I’d love to know what is wrong about the problems they have described.

  • Is that due to flatpak sandboxing?

    Edit: it’s interesting, this repo is saying the opposite, https://github.com/trytomakeyouprivate/Recommended-Flatpak-Apps/blob/main/Apps/Browsers.md

    The Flatpak Sandbox restricts the Browsers abilities to isolate the processes from another, and also valuable internal data like your history or passwords.

    Edit 2: since folks are asking further details are linked in the article. Keep in mind I am not personally making these claims, I am in learn mode just like a lot of other folks.

    From https://seirdy.one/notes/2022/06/12/flatpak-and-web-browsers/:

    When distributing browsers through Flatpak, things get a bit…weird. Nesting sandboxes in Flatpak doesn’t really work, since Flatpak forbids access to user namespaces

  • Quick addition, I think for the messy argument the way I would articulate it for folks running servers is it helps you move from pets to cattle.

  • So does Fedora Silverblue for the record.

    It is a damn impressive feature to realize you just broke your install and are able to say “no problem”.

  • As someone who bought a Steam Deck this summer, feels bad man

  • Refactoring is something that should be constantly done in a code base, for every story. As soon as people get scared about changing things the codebase is on the road to being legacy.

  • It’s crazy how good this is, from a software engineering perspective I have no idea how they pulled this off. Morrowind is such a complex game, not sure how they reverse engineered it.