• OctopusNemeses
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    24 hours ago

    KDE has a history of doing that. Plasma widgets are a gaping security hole. You can poke a hole through root. I’m pretty sure you can traverse up the JS object hierarchy from a widget and modify the whole desktop in anyway you want. At least at some point this was possible. A widget can and has deadlocked plasmashell from even loading. Their response was basically “works as intended” and closed the issue.

    • Zamundaaa@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      1
      ·
      40 minutes ago

      Plasma widgets are a gaping security hole.

      Aka “thing that isn’t sandboxed, never has been sandboxed, and never has been claimed to be sandboxed, is in fact not sandboxed”. Just like any app from your distro repositories, or appimages, or games in Steam… Or even most Flatpaks by default for that matter.

      Widgets being sandboxed would be cool and is a long term goal (which is way easier said than done!), but don’t present them not being sandboxed as some irresponsible thing someone does because they don’t care. Your expectations of security simply are simply completely misplaced.