Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If you manually install a rpm, deb or add a new repo, your system is completely owned by the person who built that package or repo

True, and the same is true for flatpak given that the author of the package controls the sandboxing.

The only solution is to have 1 or 2 trusted packagers to review the package, including its code - which is what some Linux distributions do.

Furthermore, Debian does a long release freeze for the stable release and a lot of users test it. A malicious package might well be spotted.

Contrast it with the very lightweight vetting that is done by others.



Flathub actually does review submissions reasonably well. You have to give a justification for each permission you request and why it couldn't be done in any other way.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: