You are viewing a single thread.
View all comments View context
43 points

Just use trusted repos 👍
We have GPG for a reason.

permalink
report
parent
reply
29 points
Deleted by creator
permalink
report
parent
reply
33 points
*

Possibly, but Firefox & Chrome based browsers have the same built-in isolation and other security measures as on Windows. Plus you can use Ublock Origins to get rid of malvertisements. If you really wanted, you can also isolate the browser entirely with something like firejail.
Hardend forks like LibreWolf are good too.
Oh, and Wayland also isolates clients from each other too.

I don’t think it’s that big of a threat as long as you keep some level of common sense.

permalink
report
parent
reply
3 points

And if it’s flatpak, it should be contained

permalink
report
parent
reply
3 points

Oh, and Wayland also isolates clients from each other too.

One of the biggest reasons I might want to say goodbye to xfce sooner than later.
I can’t make use of most of Waylands’ features and improvements, but this kind of isolation is very much worth it anyway.

permalink
report
parent
reply
3 points

Okay, what happens if your repo doesn’t have a specific software you are looking for? A trusted repo is good, but it won’t have everything you might want. This is especially true for new software or less popular software.

permalink
report
parent
reply
6 points
*

Install nix, flatpack, etc. ◉⁠‿⁠◉

permalink
report
parent
reply
2 points

You audit the code

permalink
report
parent
reply
13 points

There are a lot more ways to sneak malware into a system. Especially if some apps aren’t being maintained anymore. Linux is definitely safer, but you shouldn’t let your guard down

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
7 points

especially if you’re a developer. There are a lot of shenanigans going on with malware npm packages that prey on easy typos. I imagine it’s the same with other library installers for other languages too

permalink
report
parent
reply
3 points

Funny you bring this up because it’s exactly what I was thinking of. A million small packages and dependencies and who knows if the repos got hijacked

permalink
report
parent
reply

linuxmemes

!linuxmemes@lemmy.world

Create post

I use Arch btw


Sister communities:
Community rules
  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

Community stats

  • 7.5K

    Monthly active users

  • 1.2K

    Posts

  • 66K

    Comments