Martin Steigerwald - 04.08.20, 06:34:22 CEST:
> Haines Brown - 04.08.20, 01:58:26 CEST:
> > I've been relying on zoom on a laptop runnding debian. But there's a
> > problem with it and I want to install zoom on beowulf 3.
> > 
> > But there's no zoom in the beowulf repository. Do I have to download
> > debian's zoom .deb?
> 
> I used flatpak to install Zoom.

By the way I am not recommending to use Flatpak to install just *any* 
app.

I only use it for stuff that I cannot obtain via Devuan or in this case 
on this laptop Debian package repository.

I agree with the assessment at¹ enough to avoid using it to install 
something that I can easily obtain via the official package repository of 
the distribution. But compared with using the Debian package from Zoom, 
it may have the advantages I described. Of course if you monitor the 
Zoom webpage with the Debian package daily and install a new package 
immediately you may install security fixes more quickly. There is likely 
to be *some* delay regarding updated Flatpaks, but as written I receive 
updates of it regularly.

And with installing the deb package from Zoom you need to trust them 
completely. They could do anything on your computer as maintainer 
scripts run with root permissions.

Also you cannot restrict permissions of the Zoom application like you 
can with Flatseal this way.

So I personally see an security advantage of using Flatpak for third 
party, closed source apps like Zoom, Skype, Teams.

The best approach from a security point of view however is to avoid 
those apps completely.

If you use the Debian package, or even with the Flatpak, you can setup 
up a different use or use a VM, to contain the application. For now I 
rely on what Flatpak can do, but a different user or a VM of course gives 
stronger guarantees about security.

[1] https://flatkill.org/

Ciao,
-- 
Martin


_______________________________________________
Dng mailing list
[email protected]
https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng

Reply via email to