i.imgur.com

Spectacle8011, to linux in If only more Linux programs followed sandboxing best practices...
@Spectacle8011@lemmy.comfysnug.space avatar

What really needs to happen:

Flatpak packages should ask for every permission they need, and the user needs to approve every one of them.

Right now, we have this weird in-between state where some flatpak packages ship with limited permissions (like Bottles). That’s because every permission the package asks for is immediately granted. The user doesn’t get a chance to refuse these requests. This current model serves to make life more difficult for non-malicious flatpak packagers while failing to protect users from malicious packages.

Also, GNOME needs a Flatpak permissions center like KDE. You shouldn’t need to install a third party program to manage permissions.

miss_brainfart,
@miss_brainfart@lemmy.ml avatar

Absolutely, permissions should be disabled by default, and only when the app needs to do something that requires a certain permission should it ask for it.

Maybe even do something like Android, where permissions automatically get revoked if you don’t use an app for a certain time. I love that feature.

oldfart, (edited )

It’s the first time I hear someone praise Android messing with user’s settings. Care to elaborate why you like it?

miss_brainfart,
@miss_brainfart@lemmy.ml avatar

There is very little reason any app should keep its permissions if you never actually use it, is there?

Especially when most people use apps that phone home every last piece of data they give them access to.

oldfart,

I don’t agree but I see your point, that would certainly be useful to some people. Thank you for explaining.

miss_brainfart,
@miss_brainfart@lemmy.ml avatar

I think it’s enabled by default, but you can also just disable it for specific apps.

But if you leave it enabled and permissions get revoked after a while, you’ll get a notification telling you about it. I think that’s fair.

There’s always going to be a debate on whether something like this should be opt-in or opt-out, but for the purpose of privacy and data security, it makes sense to be on by default, I reckon.

JoYo,
@JoYo@lemmy.ml avatar

it’s weird that android and ios already provide this but THE container standard doesn’t

anon5621,
@anon5621@lemmy.ml avatar
Spectacle8011, (edited )
@Spectacle8011@lemmy.comfysnug.space avatar

I don’t doubt it, but this is a good place to start.

This claim has interesting phrasing:

Adding X11 sandboxing via a nested X11 server, such as Xpra, would not be difficult, but Flatpak developers refuse to acknowledge this and continue to claim, “X11 is impossible to secure”.

If you look at the GNOME post, you’ll see they haven’t argued against including a nested X server at all:

Now that the basics are working it’s time to start looking at how to create a real sandbox. This is going to require a lot of changes to the Linux stack. For instance, we have to use Wayland instead of X11, because X11 is impossible to secure.

I’m not saying they haven’t refused to acknowledge this elsewhere, but it’s strange to point to this blog post which acknowledges that the sandbox is very much a work-in-progress and agrees with Madaidan that X11 is hard to secure.

Does Xpra provide better sandboxing than XWayland? If not, I think the Flatpak developer’s solution to this is: just use Wayland. And obviously, there’s plenty of room to improve with the permissions Flatpak does offer.

I did some searching on the Flatpak Github for issues and found that you can actually use Xpra with Flatpak, and the answer is “just use Wayland”:


This is also concerning:

As odd as this may sound, you should not enable (blind) unattended updates of Flatpak packages. If you or a Flatpak frontend (app store) simply executes flatpak update -y, Flatpaks will be automatically granted any new permissions declared upstream without notifying you. Using automatic update with GNOME Software is fine, as it does not automatically update Flatpaks with permission changes and notifies the user instead.

Source: privsec.dev/posts/linux/desktop-linux-hardening/#…

It’s great that GNOME Software notifies you when permissions change! I don’t use Flatpak enough to know, but I hope flatpak update notifies you too if you don’t use the -y option.

fossisfun,
@fossisfun@lemmy.ml avatar

I’ve tried to combat this a bit with a global Flatpak override that takes unnecessarily broad permissions away by default, like filesystem=home, but apps could easily circumvent it by requesting permissions for specific subdirectories. This cat-and-mouse game could be fixed by allowing a recursive override, such as nofilesystem=home/*.

But even then, there is still the issue with D-Bus access, which is even more difficult to control …

I think it is sad that Flatpak finally provides the tool to restrict desktop apps in the same way that mobile apps have been restricted for a decade, but the implementation chooses to be insecure by default and only provides limited options to make it secure by default.

TeryVeneno,

I think the main reason why the implementation is insecure by default is simply because when it started most applications did not use portals and many portals we have today did not exist. You had to poke holes in the sandbox to make anything work cause all applications expected to run unconstrained. In the future as more apps become flatpak aware this should stop being an issue.

soupspoon, to mildlyinteresting in Front and back of $100 bill, real vs movie prop

I was wondering who signed the fake money and found this

It had never occurred to me that there’d be lots of competing companies in the business of making fake money, but it makes sense

eusousuperior,

Interesting read

capital, to memes in Which pill do you choose?

Used to want the red pill but I have a kid now. Resetting would almost assuredly cause me to end up with a different kid.

I’m team blue.

ZoopZeZoop,

There’s a related movie that I highly recommend: About Time.

Blaze,

Very good movie

capital,

Oh yeah I love that movie. I have it on my server.

Elaine,

This. My kids and my pets - I’d be haunted for the rest of my life knowing I traded them in. I’ll take the 10 mill and be happy.

grue, to lemmyshitpost in Coincidence?!

You joke, but meteorite impacts causing large igneous provinces on the opposite side of the planet might actually be a thing.

(Uluru and Meteor Crater are provably not an example of this, though, for several reasons: they aren’t antipodes of each other, Uluru is five orders of magnitude older, and the phenomenon I mentioned would’ve been caused by way, way bigger impacts.)

Aussiemandeus,
@Aussiemandeus@aussie.zone avatar

I read igneous as indigenous and went into that wiki very confused for a moment.

On the upside it got me there to donate to Wikipedia

technicalogical, (edited )

Imagine tossing a rock in the ocean so hard that the ripples converge on the other side of the globe. That’s wild…

Edit: seismic ripples

justlookingfordragon,
@justlookingfordragon@lemmy.world avatar

It’s astounding that one can learn really cool and interesting stuff by posting random nonsense to the shitpost community, lol. Thanks for the link! That was indeed new to me ;)

Yondoza,

There is correlation evidence on Mars too! I don’t think it’s been considered casual at this point, but Atlas Pro has a really cool YouTube video showing a lot of potential examples. The Hawaiian Islands were particularly convincing to me. I’ll try and find the video.

letsgo,

Do they have to be antipodal? If we imagine a clock face overlaid over an image of the earth, if a meteorite strikes vertically (i.e. parallel to the 12-6 line) at 11, could it result in a bulge at 7?

flipflop97, (edited ) to piracy in it sure beats having to buy it, but seriously come on...
@flipflop97@feddit.nl avatar

You can do it yourself:

ocrmypdf.readthedocs.io

jlow,
gregorum, (edited ) to risa in Q intentionally leaves his cart in the blind spot behind the most expensive car in the lot
someguy3,

This one is accurate.

Anticorp,

Has a personal entourage who would die to return his cart.

Mycatiskai, to memes in This is the year, guys.

Nobody might want advice here and feel free to vote this down but go out into the real world and find something to do where other people are.

A little more than 7 years ago, after being single for 6 years, I went to a dog park with my dog and met a woman that interested me. We showed up at the same time and talked each time, I asked her out after a month. We went out New Year’s Eve and have been together since.

It doesn’t always work but you can do it, random meme watchers have done it, so it is possible.

gmtom,

Thanks but the type of people I’m into don’t go to dog parks.

Mycatiskai,

The first paragraph still applies. Go out into the world and find something to do with other people.

sbv,

Thanks but the type of people I’m into don’t go out into the world.

blanketswithsmallpox, (edited )
MycelialMass,

Go to a cat park instead

answersplease77,

you can shove the whole dog park up your butt if you don’t have an income that can support a relationship. It was never about anything else

Mycatiskai,

If you find a good partner, you split costs and things are cheaper when only paying half, an equal partner in everything.

If you have a shit partner that expects you to pay for everything then yes you are going to have a bad time.

I hope you find someone that you can share your life with equally.

answersplease77,

It sucks such thing does not exist where I’m from. Even if she was earning 10x times more than you, she does not contribute a penny to your kids , house or bills. I’m not making this up

Mycatiskai,

Time to move then, if you can’t have an equal life partner then go somewhere you can.

answersplease77,

not possible due to our situation. me and my family are travel banned by the government, siblings in jail, and Im the only one with my mom. it sucks I know

rotopenguin,
@rotopenguin@infosec.pub avatar

Thanks, but I only take advice from the Arch Wiki.

xthexder,
@xthexder@l.sw0.com avatar

$ man dating

I_am_10_squirrels,

whois grindr

rotopenguin,
@rotopenguin@infosec.pub avatar

nslookup hookup

blaine, (edited )

I tried this once. Went to the dog park, chatted up a girl over a period of a month. I finally got the courage to ask her on a date, and she said yes! The date (dinner and a local concert) went great - we ended up back at my place and I can honestly say it was some of the best sex of my life.

Then she ghosted me and we never talked again. That was 2017, and I’m still not over it. Thanks for the advice though.

Mycatiskai,

I’m definitely not promising it will work perfectly. I was single with a dog and going to dog parks for 5 years before that but was at first not ready to date as I had just separated from my partner of 9 years.

Dog parks are just good places to meet people, some you won’t know their names, some you will know them by their dog’s name, some you will know their names and meet outside of the dog park.

Being social is the key to whatever type of relationship you want.

lolcatnip,

Too bad I usually hate being social.

Mycatiskai,

Then you don’t really want a girlfriend/boyfriend/partner because that is being social.

lolcatnip,

Cool, tell me more about what I really want, since you know me so well.

Auzy,

Funny you say that… Because, for the first half, I genuinely thought you were my housemate

phoenixz,

Don’t get too high hopes about people until you really know them. So it was the best sex ever? Cherish that memory but don’t stop living. And 2017, and you’re still not over that? Really dude (or dudette?), don’t just get over that, get over yourself. Stop stop living, start living. Take risks, get hurt. Yes, you’ll get some bruises along the way, it will build character, you will learn and improve until you find that perfect person and by then it will not only be that that person is perfect for you, you will then also finally be perfect for that person because honestly right now you don’t sound perfect for anybody. Don’t that that last bit wrong, it just means you gotta work on yourself. Relationships are a lot of work, I spent huge amounts of time on reflecting, thinking about how I can make my wife smile, trying to improve myself, etc…

I make a point of it to smile. Every. Single. Time. That. I. See. Her. I do anyway because she’s fucking gorgeous, but even so, i make sure. It makes her day multiple times per day, and seeing her smile makes me smile even more. A real relationship is a lot of work and it’s so damn worth it, but you gotta be ready for it too. If you’re not willing to do the work now how are you supposed tondo the work once you find that special someone?

You gotta get out there, and get hurt. It’s part of the process. I got hurt (and unfortunately hurt others myself) on multiple occasions and I’m fine. You’ll be fine. It sucks in the moment, but you process it, give it a space somewhere in your memories and you go on to the next one. Believe me, you will get hurt a few more times (and build great memories in the process too, by the way, let’s not forget that), you will learn what to do, what not to do, you’ll learn not to immediately get strung up by the first girl and declare her your undying love within 5 minutes of meeting her, that usually doesn’t end well. Also not the second girl, nor the third , and not within 5 minutes… after a while you’ll find that super special one.

like that you will get better because it’s not only about the others, its about you too. Grow up.

As long as you stay safely on your shelter, you will stay alone for your entire life. If that’s what you want, fine. But I think it’s not, so this year go out, get out, take risks, get hurt, be happy.

Happy new year!

Heliumfart, to mildlyinteresting in Braille graph paper

How many micrograms?

coaxil,

1200, we are going to touch gods asshole!

ShunkW,

I was gonna say, this looks more like blotter paper than braille.

moistclump,

Ohh, yes that makes much more sense. I was trying to figure out why a blind person would need to graph soemthing out.

When it doubt, the answer is drugs. Always drugs.

GraniteM,

The paper was in with a bunch of braille GED study books. One might need to do some graphing to get one’s GED.

Deuces,

Graphing is still necessary for the blind, but it’s more common to use a plastic sheet on a hard rubber clipboard with a stylus that causes the plastic to rise up when it’s pressed with a bit of force. (Though while googling for it I found plenty of examples like yours so maybe less common than I thought)

www.aph.org/product/tactile-drawing-film/

meowMix2525,

Pretty sure they’re joking just about the resemblance. cause blotter paper is flat…

slushiedrinker, to piracy in I have received a copyright infringement alert, what should I answer?

Say nothing. Stop sharing or seeding. But, above all, say nothing. You’re getting phished. Just comply and stop seeding the shit. Keep quiet. If you reply you’ll just have problems that cost money.

bandario,
@bandario@lemmy.dbzer0.com avatar

This. Make the bastards chase you.

ArbitraryValue, to unethicallifeprotips in Rent requirements in the US are nuts

They don’t check your credit? They checked my credit the last time I rented.

Also you don’t need to photoshop when it’s easier to edit the html.

wintermute_oregon,

Credit doesn’t show income. It is just a score with income not factored in.

mosiacmango,

Experian offers a service called “theworknumber” that will sell you income data to anyone for $60.

You cant opt out because fuck american laws, but you can demand they “freeze” it like credit, so any inquiry is just rejected.

wintermute_oregon,

That may solve who’s texting me if I’d like to sell a property. They keep asking me about properties i haven’t owned for years but I use to live at.

Trainguyrom,

At least you get texted about properties you once owned. I get texted about some dude’s properties across the country even though this hasn’t been his number for a good decade now

wintermute_oregon,

Haha it’s just weird to get a txt asking if I want to sell x property I haven’t owned for twenty years.

It has to be a credit report thing as my gf gets txt about the properties and she has never been on the loans or titles. The properties are always in my name.

GlitzyArmrest,
@GlitzyArmrest@lemmy.world avatar

This is where you can request a form to freeze this BS:

employees.theworknumber.com/employee-data-freeze

Notably it’s not as easy as freezing your credit. Probably because there aren’t as many laws around it.

ManosTheHandsOfFate,
@ManosTheHandsOfFate@lemmy.world avatar

You can have good credit and a low salary.

Potatos_are_not_friends,

I had 800 credit working fast food because l carried extremely little debt.

Twenty years later, my score is fighting to stay about 750 because I make 6 figures, a few credit cards with zero debt. Because they WANT me to hold onto debt to show my trustworthiness? Fuck that.

Corkyskog,
@Corkyskog@sh.itjust.works avatar

Yes, they do. You get extra points for holding a balance.

Cryophilia,

No you don’t. Technically you get a small (~10 point) bonus for showing literally anything other than $0. But you get zero points for carrying that balance beyond the payoff date.

You should never ever ever pay interest on credit cards. It doesn’t help you in any way.

stevehobbes,

Nah, there’s something else that’s triggering it. Average length of credit matters a lot, so if you cancel cards and get new ones frequently that would do it.

Long term debt for sure is good, carrying balances on cards is never rewarded.

The reason they’re OK extending credit when you have debt is because they can see you are managing it. Mortgage or auto loans (asset backed) aren’t bad. Don’t carry balances on cards ever if you can avoid it.

As another poster said, there’s probably no functional difference for you between 750 and 830.

habanhero,

Landlords also ask for pay stubs / proof of income.

jivemasta,

Yes, but also you don’t get good credit by entering into contracts you can’t afford. What I can and can’t afford are my decision to make.

Just like you can have good credit and low income, you can have high income and be shit with money. It really doesn’t prove anything by showing a pay stub.

eluvatar, to memes in title

Hell yeah

steal_your_face,
@steal_your_face@lemmy.ml avatar

Hell yeah

The_Picard_Maneuver, to risa in Q intentionally leaves his cart in the blind spot behind the most expensive car in the lot
@The_Picard_Maneuver@startrek.website avatar
ininewcrow,
@ininewcrow@lemmy.ca avatar

When I see people like that … I usually turn around and drive to the next town

instamat, to memes in any Death Grips fans here?
Sailing7,

The fuck is this abomination?

Theharpyeagle,

Death Grips is car jamming music, you really gotta get into that mood for it.

A_Brave_Wanderer,

Either an experimental masterpiece or noisy dogshit depending on who you ask.

Sailing7,

Well I can say for myself I am the second kind of person.

HerbalGamer,
@HerbalGamer@sh.itjust.works avatar

I don’t hate it…

velox_vulnus,

deleted_by_author

  • Loading...
  • June,

    Ok boomer.

    It’s not 💯 but I liked it.

    NoSpiritAnimal, (edited )
    @NoSpiritAnimal@lemmy.world avatar

    Your last post is about loving pre-80s bollywood music. You can keep your farts and opinions to yourself. May as well listen to a lathe turn.

    velox_vulnus, (edited )

    deleted_by_author

  • Loading...
  • NoSpiritAnimal,
    @NoSpiritAnimal@lemmy.world avatar

    well, you’re listening to one anyway. Your prejudiced behavior is oozing out, a map is your biggest enemy is a map, dear, and no, Taco Bell is not that hot - it’s a you problem. Your ignorance is in full display, you know nothing about the culture outside of your borders. Truly pathetic.

    I’m just mirroring your energy scooter. If there is prejudgement it’s coming from your end.

    youtu.be/BB6KvXQx090?si=5JeJCmeBupFasoF7

    Wow, that sucked.

    Dagnet, to mildlyinteresting in How geologists collect lava

    That’s so weird. Why doesn’t he just fill the bucket with lava? That way he can place a lava source block wherever he wants! Maybe set fire to his friends creations in the process.

    Annoyed_Crabby,

    Dude just want obsidian quick

    CarbonIceDragon, to risa in Just a little bit
    @CarbonIceDragon@pawb.social avatar

    I mean, I sort of imagine it to be less the “rule on the books” part, and more the “do we actually have the physical capacity to enforce those rules” end of it. They cant really imprison him (I mean while he’s feeling guilty he might stay willingly, but they cant keep him in if he eventually changes his mind, so itd more be him imprisoning himself). Trying to despite the futility of it would seem somewhat dangerous, because again, if he should ever change his mind, you clearly dont want to seem hostile to something with that kind of power, especially when you dont have it. Saying “Our law is not sufficient for you” could just be interpreted as the most diplomatic way given his mental state to justify leaving and not returning.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #

    Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 18878464 bytes) in /var/www/kbin/kbin/vendor/symfony/http-kernel/Profiler/FileProfilerStorage.php on line 171

    Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 4210688 bytes) in /var/www/kbin/kbin/vendor/symfony/error-handler/Resources/views/logs.html.php on line 31