I usually trust my distro repos without checking. Can the same be applied to flathub without much worry?

  • ZephrC
    link
    fedilink
    401 year ago

    I’ve never heard of anyone getting an unsafe package from flathub, but they certainly aren’t all as thoroughly vetted as stuff from a well maintained distro. Any major package is almost certainly fine, but if you’re downloading something obscure I’d use Flatseal to make sure it’s very well sandboxed, just in case.

    They’ve also recently added verified checkmarks to the website for flatpaks that are officially maintained by the developers of the app, so that’s another thing to look out for.

    • @Raphael
      link
      131 year ago

      Canonical is a disgrace.

  • @Unkend
    link
    25
    edit-2
    1 year ago

    deleted by creator

    • @[email protected]
      link
      fedilink
      11 year ago

      Needlessly reductionist, but also wrong. If your code is proven to work (like, machine verified), and you use a compiler that is also verified to generate correct code, then that code is secure.

  • @RegalPotoo
    link
    181 year ago

    They aren’t inherently safe. I don’t have any examples of Flatpak packages off FlatHub being poisoned, but FlatHub does allow “community” maintained packages - as in, someone unaffiliated with the development team of an app packages and publishes the app to FlatHub. That would seem to be a really good place to get into a supply chain if you were a bar actor.

  • Xylight (Photon dev)
    link
    fedilink
    171 year ago

    Flathub apps will likely be removed quickly if they’re found to be malicious. They’re slightly more unsafe than official repos, but you should be fine. Make sure to carefully check apps with like 4 downloads though.

  • qwesx
    link
    fedilink
    161 year ago

    Even disregarding the trust issues with Flatpak packages made by random people: Packages often contain versions of some libraries in order to not depend on the distro’s. If there are security vulnerabilities in a library then the distro maintainers usually fix it very quickly (if not go find a better distro) and it’s fixed for all packages on your system that depend on it. But this doesn’t apply to Flatpak where the package providers have to update the libraries in their own package - and the track record isn’t great. Sandboxing doesn’t help if that vulnerability leads to wiping your home directory.

  • ono
    link
    fedilink
    12
    edit-2
    1 year ago

    No, they are not always safe.

    Be picky about what you install, and vigilant about permissions.

  • @Grangle1
    link
    101 year ago

    Flathub is likely safer than most other places to get flatpaks from, certainly safer than just some random repo you find on some guy’s website somewhere, but no software source is guaranteed to be 100% safe.

  • @[email protected]
    link
    fedilink
    71 year ago

    At https://blog.frehi.be/2023/04/23/the-security-risks-of-flathub/ someone has published an article about Flathub in which he addresses a few problems.

    Therefore, the answer is that Flathub is not always safe to use. However, I do not know of any package source that is always safe to use. Is Flathub more insecure than other package sources? I can’t answer that because I don’t use solutions like Flatpak, AppImage etc. myself.

    • z3bra
      link
      fedilink
      21 year ago

      It’s more about trust, than security. When you use a specific distro, you only have to trust the distro packagers. These packages are reviewed by multiple persons, tested thoroughly and (usually) built in a reproductible way. The packagers are usually different from the developers, so they can also review the code itself and eventually patch issues if needed to be in line with the distro’s ideology.

      With flatpak, snap and friends, anyone is a potential packager, so for each software you gotta trust this single entity, which is usually the developer itself.

    • @[email protected]
      link
      fedilink
      11 year ago

      I can: yes, Flathub is more unsafe than package managers that actually verify all packages signatures after they download software.

  • @Raphael
    link
    71 year ago

    Not 100%, it’s not very hard to push packages to Flathub.

  • @[email protected]
    link
    fedilink
    31 year ago

    On the contrary, downloading files from flathub are never safe because it does not verify signatures, unlike secure package manager like apt

  • @j4k3
    link
    31 year ago

    The general community is probably going to catch any issues that pop up extremely quickly. Like my main machines are all on whitelist firewalls residing on external devices. If any software tries to make odd connections, the connections will get dropped and logged. I wouldn’t hesitate to report anything odd. I don’t run sketchy proprietary junk for the most part.

  • @gobbling871
    link
    -91 year ago

    Yes. Flathub aims to replace your distro’s repository as the source for non-system packages.