Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Conversation

Notices

  1. Kinmen Rising Project-金門最後才子🇺🇦 (kinmenrisingproject@g0v.social)'s status on Thursday, 28-Jul-2022 14:05:37 UTC Kinmen Rising Project-金門最後才子🇺🇦 Kinmen Rising Project-金門最後才子🇺🇦

    I cleaned the folder of the ppa repositories... it was time. Still had commented repos of bionic... tools not developed anymore, various garbage

    In conversation Thursday, 28-Jul-2022 14:05:37 UTC from g0v.social permalink
    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 14:43:00 UTC Bernie Bernie
      in reply to

      Last week I had to use the #Skype on my #fedora laptop. As a precaution, before installing the rpm I checked for post-install scripts:
      https://codewiz.org/pub/skype-rpm-scripts.txt

      This adds a dnf repo and a GPG key to the rpm keyring. This enables automatic updates, but there's no corresponding post-uninstall script to remove these.

      From this point on, #Microsoft is permanently trusted to "update" any software on my laptop 😱

      @KinmenRisingProject

      In conversation Thursday, 28-Jul-2022 14:43:00 UTC permalink

      Attachments


    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 15:04:48 UTC Bernie Bernie
      in reply to

      A user would have to know how to delete their repo and uninstall Microsoft's RPM key.

      So I got curious. Who else is trusted to install rpms on my Laptop? Here's how you could tell:

      rpm -q gpg-pubkey --qf '%{NAME}-%{VERSION}-%{RELEASE}\t%{INSTALLTIME:date}\t%{SUMMARY}\n'

      I had dozens of old keys from all sorts of vendors, including Google (Chrome) and another one for Microsoft (for VSCode).

      @KinmenRisingProject

      In conversation Thursday, 28-Jul-2022 15:04:48 UTC permalink
    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 15:05:56 UTC Bernie Bernie
      in reply to

      Perhaps it's worth restating that downloading binaries directly from vendor websites is bad security practice.

      Linux security is no better than Window's if you effectively give anyone root access to your machine.

      @KinmenRisingProject #linux #security

      In conversation Thursday, 28-Jul-2022 15:05:56 UTC permalink
    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 15:12:48 UTC Bernie Bernie
      in reply to

      Installing #Skype via #flatpak would have been marginally better.

      Kudos to Gnome Software for prominently displaying the risks.

      @KinmenRisingProject

      In conversation Thursday, 28-Jul-2022 15:12:48 UTC permalink

      Attachments


      1. https://media.mstdn.io/mstdn-media/media_attachments/files/108/725/595/941/782/865/original/e8084a2b6f215ce9.png
    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 15:24:21 UTC Bernie Bernie
      in reply to

      Though for some reason #Gnome Software shows a version of Skype that's 2 years out of date.

      Not very secure either!

      In conversation Thursday, 28-Jul-2022 15:24:21 UTC permalink

      Attachments


      1. https://media.mstdn.io/mstdn-media/media_attachments/files/108/725/624/944/851/681/original/b33219a59b771aef.png
    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 15:26:40 UTC Bernie Bernie
      in reply to

      Strange, #Flathub has the latest version of Skype from this month:
      https://flathub.org/apps/details/com.skype.Client

      In conversation Thursday, 28-Jul-2022 15:26:40 UTC permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Flathub—An app store and build service for Linux
        Find and install hundreds of apps and games for Linux. Enjoy GIMP, GNU Octave, Spotify, Steam and many more!
    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 15:32:07 UTC Bernie Bernie
      in reply to
      • Martín Abente Lahaye

      Oh, the old version is from flathub-beta.

      @tchx84, is this a bug in Gnome Software? Or is it expected that older packages in flathub-beta would always take precedence over flathub?

      In conversation Thursday, 28-Jul-2022 15:32:07 UTC permalink

      Attachments


      1. https://media.mstdn.io/mstdn-media/media_attachments/files/108/725/666/232/734/005/original/7c2d997e69916a92.png
    • Bernie (codewiz@mstdn.io)'s status on Thursday, 28-Jul-2022 15:46:45 UTC Bernie Bernie
      in reply to
      • Martín Abente Lahaye

      Oh, I see. It happens because the flathub-beta repo was a --system repo, while flathub was a --user repo.

      If both are configured as --user, then Gnome Software lets me pick one. Otherwise, it shows only the --system one.

      Still smells like a bug, @tchx84. Do you know a developer who could look into it?

      In conversation Thursday, 28-Jul-2022 15:46:45 UTC permalink

      Attachments


      1. https://media.mstdn.io/mstdn-media/media_attachments/files/108/725/729/295/438/970/original/e6b68d5556c12fa9.png
    • Bernie (codewiz@mstdn.io)'s status on Sunday, 31-Jul-2022 00:41:49 UTC Bernie Bernie
      in reply to
      • Martín Abente Lahaye

      #Plasma Discover recently merged a nice fix for this sort of problems:
      https://invent.kde.org/plasma/discover/-/merge_requests/339

      @tchx84

      In conversation Sunday, 31-Jul-2022 00:41:49 UTC permalink

      Attachments

      1. Sign in · GitLab
        GitLab Community Edition

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.