• Rustmilian
    link
    English
    437 months ago

    Just use trusted repos 👍
    We have GPG for a reason.

      • Rustmilian
        link
        English
        33
        edit-2
        7 months ago

        Possibly, but Firefox & Chrome based browsers have the same built-in isolation and other security measures as on Windows. Plus you can use Ublock Origins to get rid of malvertisements. If you really wanted, you can also isolate the browser entirely with something like firejail.
        Hardend forks like LibreWolf are good too.
        Oh, and Wayland also isolates clients from each other too.

        I don’t think it’s that big of a threat as long as you keep some level of common sense.

        • @[email protected]
          link
          fedilink
          37 months ago

          Oh, and Wayland also isolates clients from each other too.

          One of the biggest reasons I might want to say goodbye to xfce sooner than later.
          I can’t make use of most of Waylands’ features and improvements, but this kind of isolation is very much worth it anyway.

          • Rustmilian
            link
            English
            27 months ago

            Xfce does have a w-i-p porting effort to Wayland.

            • @[email protected]
              link
              fedilink
              37 months ago

              I have confidence that they’ll do it right, but looking at its past, it will take a looong while until it’s ready

              • Rustmilian
                link
                English
                2
                edit-2
                7 months ago

                True, but at least development is steady for now. Maybe in a few years.

    • @[email protected]
      link
      fedilink
      English
      137 months ago

      There are a lot more ways to sneak malware into a system. Especially if some apps aren’t being maintained anymore. Linux is definitely safer, but you shouldn’t let your guard down

      • @[email protected]
        link
        fedilink
        77 months ago

        especially if you’re a developer. There are a lot of shenanigans going on with malware npm packages that prey on easy typos. I imagine it’s the same with other library installers for other languages too

        • @[email protected]
          link
          fedilink
          English
          37 months ago

          Funny you bring this up because it’s exactly what I was thinking of. A million small packages and dependencies and who knows if the repos got hijacked

      • Rustmilian
        link
        English
        1
        edit-2
        7 months ago

        deleted by creator

    • Dizzy Devil Ducky
      link
      fedilink
      English
      37 months ago

      Okay, what happens if your repo doesn’t have a specific software you are looking for? A trusted repo is good, but it won’t have everything you might want. This is especially true for new software or less popular software.