Could the same thing happen on Flathub? Considering the number of unverified packages on the platform
My understanding is that flatpaks run in a sandbox, so although there is a risk- especially for what you give permissions to- it’s not exactly the same. The AUR is basically “curl | bash”, it’s a miracle this hasn’t happened before. If you’re worried about it I think flatseal can look at the permissions and such, but you’re probably fine.
Nope, the security is basically a gate in the middle of a field.
Just check the permissions of an app before installing. Bazaar has a gauge for how “safe” an app is based on permissions. If it doesn’t request internet, filesystem access, and other powerful permissions, it’ll be marked as the safest.
Really it’s the same as docker. It’s secure most of the time, but don’t come crying about getting hacked if you give all your containers access to /dev, host networking, etc
“App with access to files can access files”
And “we won’t tell you which ones can”
Well, both the Flathub website and KDE Discover list this, so this seems like a GNOME issue and not a Flatpak issue.

KDE Discover:

Yeah that post is 5 years old, I would think a lot of that has changed by now
Ha! That sucks. I appreciate that article but now I’m having a little bit of an existential crisis.
now I’m having a little bit of an existential crisis.

Well shit.
While they are sandboxed, there is still potential for them to cause harm. Its in theory a safer system, but nothing is full proof. I’d agree that its likely fine but best to be cautious
Hacked accounts next
After one year of using Linux, I’m starting to get the memes.
Well these accounts are probably making first commit so it can also be easily found
Alternatively, the first wave of malware stole the accounts of actual contributors. The same method was used in npm afaik.
That actually had me laugh.





