[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: a two cent suggestion



Hakan Bayındır wrote: 
> 
> 
> I think AppImages are great (from my perspective) for allowing people to run
> whatever they want on their systems, without getting root privileges and
> having a sandboxed, hermetically sealed application with batteries included.

If they actually did that, it would be great.

* sandboxing is optional (and in the control of the developer,
  not the user)

* integrity is not assured

* authenticity is not assured

* no source is trustable

The only thing that AppImage gets you is dependency assurance...
which is itself problematic if the dependencies have security or
functionality issues. Faced with a malicious source, users are 
completely helpless.

-dsr-


Reply to: