How is it possible, that Signal still only provides a .deb package and no .rpm, or even better AppImage or Flatpak? There is an unofficial Flatpak but is it secure?

You are viewing a single thread.
View all comments
23 points
*
Deleted by creator
permalink
report
reply
10 points
*
Deleted by creator
permalink
report
parent
reply
8 points

Well I think you have to distinguish between a messenger and other programms, because a messenger has a lot of sensitive data.

permalink
report
parent
reply
7 points
*

Just because something is built out of love does not make it safe, and attestation is about safety. You wouldn’t trust an un-attested surgical device, just because there’s a really positive community around its design.

Signal is a life-or-death app for some people.

permalink
report
parent
reply
2 points

What warnings?

permalink
report
parent
reply
1 point

The ‘appstore’ of some distributions, e.g. Linux Mint, displays a warning or hint for unofficial flatpaks. In Mint the display of unofficial flatpaks are toggled off by default and there is a warning or recommendation displayed against toggling on.

permalink
report
parent
reply
1 point

I’m not a developer so I can’t really check myself

permalink
report
parent
reply
12 points

I just read through the unofficial Flathub Flatpak for Signal and it is very simple. It fetches the .deb from Signal’s website, installs it in the sandbox, and uses a launcher script to tell the OS some basic toggles like should it start minimized or should it display a tray icon. In the script it makes use of zypak, which to my understanding is to tell electron (chromium) to allow sandboxing to be handled by Flatpak. Here is the repo and the build instructions is the .yaml file.

permalink
report
parent
reply
7 points

Flatpaks are pretty easy to read through. Just go to the links section of Flathub and click the manifest, then read it to see what is done during building.

permalink
report
parent
reply

Free and Open Source Software

!foss@beehaw.org

Create post

If it’s free and open source and it’s also software, it can be discussed here. Subcommunity of Technology.


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Community stats

  • 923

    Monthly active users

  • 792

    Posts

  • 10K

    Comments