

1·
26 days agoWhen a critical security bug is open for years on a project with plenty of funding to fix it…
When a critical security bug is open for years on a project with plenty of funding to fix it…
They don’t seem to give a shit about security. I think the well is poisoned. Best to just use apt
Flatpak doesn’t verify signatures like normal package managers do
So the issue isn’t that you downloaded a flatpak that included malicious code. The issue is that you downloaded a legit flatpak and ended up downloading malicious code because flatpak doesn’t verify what it downloads
The sand boxing is a distraction and doesn’t matter if you downloaded malicious code
Pretty fundementale broken IMHO. Its a security nightmare
God damn, I’ve needed this for years
Yes; it’s not an OS
Uh oh