I usually trust my distro repos without checking. Can the same be applied to flathub without much worry?

  • z3bra@lemmy.sdf.org
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    It’s more about trust, than security. When you use a specific distro, you only have to trust the distro packagers. These packages are reviewed by multiple persons, tested thoroughly and (usually) built in a reproductible way. The packagers are usually different from the developers, so they can also review the code itself and eventually patch issues if needed to be in line with the distro’s ideology.

    With flatpak, snap and friends, anyone is a potential packager, so for each software you gotta trust this single entity, which is usually the developer itself.