• Allero@lemmy.today
    link
    fedilink
    arrow-up
    8
    arrow-down
    5
    ·
    6 hours ago

    As I said, dependencies typically don’t take that much space. We’re not in the '80s, I can spare some megabytes to ensure my system runs smoothly and is managed well.

    As per naming, I agree, but barely anyone uses command line to install Flatpaks, as they are primarily meant for desktop use. In GUI, Flatpaks are shown as any other package, and all it takes is to push “Install” button.

    If you want to enjoy your chad geeky Linux, you still can. Go for CachyOS, or anything more obscure, never to use Flatpaks again. At the same time, let others use what is good and convenient to them.

    • nitrolife@rekabu.ru
      link
      fedilink
      arrow-up
      8
      ·
      5 hours ago

      It’s not the 80s, and I can save a few megabytes to keep my system running smoothly and well-managed.

      And then it turns out that you have 18 libssl libraries in diffirent fpatpacks, and half of them contain a critical vulnerability that any website on the Internet can use to hack your PC. How much do you trust the limitations of flatpack apps? are you sure that a random hacker won’t hack your OBS web plugin and encrypt your entire fpatpack partition (which some “very smart” distributions even stuff office into, and your work files will be hidden there). People have come up with external dependencies for a reason.

      • Allero@lemmy.today
        link
        fedilink
        arrow-up
        6
        arrow-down
        3
        ·
        5 hours ago

        Fair criticism!

        However, the extent of the damage is limited by flatpak and whatever permissions you have set, and, if I understand it correctly, you cannot attack one flatpak through the other unless they share access to some files.

        Also, I haven’t seen this kind of attack in the wild (maybe I’m not informed enough?) as opposed to rogue maintainers injecting malware into packages.

        On an unrelated note: apparently, there is finally some Russian Lemmy instance? That’s a welcome change.

        • nitrolife@rekabu.ru
          link
          fedilink
          arrow-up
          5
          arrow-down
          1
          ·
          5 hours ago

          However, the extent of the damage is limited by flatpak and whatever permissions you have set, and, if I understand it correctly, you cannot attack one flatpak through the other unless they share access to some files.

          there is a problem here that permissions are also set by the packages developers. User in most cases click accept all and alll done.

          On an unrelated note: apparently, there is finally some Russian Lemmy instance? That’s a welcome change.

          Well… Appeared 2 years ago. It’s just that practically no one needs it. =)

          • Allero@lemmy.today
            link
            fedilink
            arrow-up
            4
            arrow-down
            2
            ·
            5 hours ago

            Permissions are also set by the packages developers

            True, and I don’t think it is healthy not to let them to. But it would be nice to either have some vetting on the matter, or ask user about which permissions they agree for when they install Flatpak.

            Appeared 2 years ago

            Ого, то есть примерно когда я сам здесь очутился. Никогда не слышал о ру инстансах, хоть и искал. Теперь, кажется, нашёл)

            Берёте человечка на борт? Не обещаю сделать Рекабу главным инстансом, но всегда полезно быть по обе стороны Чебурнета, а то последнее время с забугорными беды бывают.