Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This works both ways: Why would you rather install some random flatpak from someone you don't know as opposed to a rpm?

The trust is outside of the scope of package managers



Because installing an rpm allows you to run arbitrary code as root. Installing a flatpak does not. I mean there are many more reasons but that should be en.


It's explained in the article, security section: b/c installing flatpak can also run arbitrary code as a user. And I won't argue that running malicious code as a user is always harmless. Regardless of root access if you're installing flatpak and its author want to pwn you - they can do it even without root access


Yeah, so why even have user accounts and not just root everything? I mean if there's no difference...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: