Hey all!

(I did post this in c/flatpak, but this community is more active. I am not sure where would be more appropriate)

Something that I have been wanting to get working is having my browser and password manager both in flatpak. I really like being sandbox and having faster updates if the distro is on the slower side perhaps.

I have a set up with Firefox as a deb and keepassxc as a flat and that works find as one would expect. I did want to install Vivaldi as a flatpak and was not able to get it to talk with keepass.

In my reading I found this: installing KeePassXC natively, which you’d actually want for security reasons.

installing KeePassXC natively, which you’d actually want for security reasons

What is mean by that line of reasoning?

  • @[email protected]
    link
    fedilink
    45 months ago

    I don’t know if this is still the case, but IIRC browsers (chrome and Firefox) have their own sandboxing which is quite effective, but their efficacy is hindered by flatpak.

      • @ozymandias117
        link
        English
        3
        edit-2
        5 months ago

        Browsers do have their own sandboxing, trying to prevent things like a JavaScript overflow on one website affecting other tabs, etc

        Flatpaks use user namespaces and run each program in their own filesystem snapshot

        Chromium in flathub has been patched to support its own sandboxing inside of the Flatpak sandbox

        Firefox only loses its user namespace, but Flatpak has already put it in its own user namespace

        The only reduction in the browsers own sandboxing is if they’re creating separate user namespaces per remote process, but in about:support, Firefox still lists itself as having the max sandbox level even in the Flatpak

        The nice thing about Flatpak is that you can restrict it even more - e.g. my browser is only allowed to touch files in ~/Downloads/firefox

        I don’t use webcams/mics through Firefox, so it also has no access to those, etc

        You can set fine grained permissions easily with a program called Flatseal to decide what your browser should be able to touch on your machine