Skip Navigation

Posts
1
Comments
139
Joined
2 yr. ago

I'm the Never Ending Pie Throwing Robot, aka NEPTR.

Linux enthusiast, programmer, and privacy advocate. I'm nearly done with an IT Security degree.

TL;DR I am a nerd.

  • The Firefox Flatpak has much weaker isolation because the Flatpak sandbox interferes with the browser sandbox. This means a malicious site can compromise other sites and even the whole browser with a single exploit instead of the two normally required (which is a significant degradation in protection). The specific part blocked by Flatpak is user namespace sandboxing by Firefox. If you can help it, DO NOT install as Flatpak. Snap does not have this problem, but nobody likes Snap. Chromium has a similar problem as a Flatpak.

  • Ok. I guess I never noticed because I actively don't like any of those features and I definitely don't want Discord to have unrestricted filesystem access. The file picker in Vesktop works for me without giving full access.

  • What features? Discord was working perfect for me on a custom client (Vesktop) but is broken now because they hate me using a VPN.

  • Honestly, I thought the post may have been making a joke about GIMP sucking or something, cus half the time I see GIMP it is people hating on its (admittedly) not-great UX.

  • I think is very dependent on the apps you install because i haven't need to do really any workarounds and i install all my apps through Flatpak. The only messing around with permissions i do is disabling everything that i dont need (like printer or smartcard access). I also have over a hundred apps installed.

  • Here is a video by the channel Dr. Fatima (former astrophysicist) which I think has some intersection with this topic. I may have picked the wrong video though because I haven't watched it in months.

    https://www.youtube.com/watch?v=eQdTmvqCgxI

  • Wydm? Rockchip copied their code, changed the license and didnt attribute FFmpeg. FFmpeg is a small team of enthusiasts who are responsible for plenty of important innovation and remain largely unpaid even with such substantial widespread use of their code in like SOOOO MANY big software projects. It isn't their fault that people aren't following the simple rules of the license to use their code.

  • I would prefer webapps to native if there was a protocol to fully load the page and disable network traffic for apps that work fully offline. It is more secure to run an app in the browser because off the layers of isolation in modern browsers. Native apps can access all sorts of information and system resources, which could be used to compromise the host OS.

  • I would prefer webapps to native if there was a protocol to fully load the page and disable network traffic for apps that work fully offline.

  • Deleted

    Permanently Deleted

    Jump
  • They used the alcohol as aftershave

  • As I mentioned, most security vulnerabilities are not reported because it may not seem security related. The distro maintainers can't keep up with every package and read all the commits, so as a result security fixes often go unfocused. It is a real big problem that many security researchers acknowledged.

  • I still would never recommend a "stable release" or LTS distro because the vast majority of security vulnerabilities never receive a CVE, and as a result the a large amount of vulnerabilities go unpatched for months. Also I like distros that take security seriously (Fedora and openSUSE).

  • It has to do with LTS kernel (iirc) making it incompatible with certain new(er) hardware. I recommend Fedora KDE.

  • I have been liking CachyOS as well. I reluctantly switched from Fedora after I kept getting weird problems (definitely a "my PC" thing, I wish I could upgrade).

    Features I like about Cachy:

    • Auto-setup of snapper btrfs snapshoting (my fav feature of openSUSE) on all bootloaders (I like the simplicity of limine)
    • Gaming ready fork of kernel-hardened, with some changes, including allowing use of unprivileged namespaces (needed by Bubblewrap/Flatpak/Firefox/Chromium to avoid the need of a SUID binary)
    • AUR (cus it is Arch)
    • Update service which updates from all installed sources (pacman, Flatpak, AUR)

    What I wish was different:

    • Inclusion of a full system Mandatory Access Control policy (SELinux preferably)
    • Compatibility with hardened_malloc (idk why but on Cachy, GTK apps crash because glycin bubblwrap commands fail)
  • Naturally. By not stealing you are giving them free money.

  • They factor the cost of theft into their item pricing.

  • It started as a fork of the now defunct Mandriva Linux. Mageia isn't a new Linux distro (in age). Otherwise it is just a normal Linux distro from what I can tell.

  • Valhiem