Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He is missing the point. Flatpak/Snap are not just an alternative way to ship binaries. They are way to isolate applications and what they can do. Landscape has moved from protecting the system or an user from another to protect the same user applications and their data from each other, specially for desktop environments. That is not even in the map for Windows, its security model and its applications. It is a big jump backwards.


Windows does a lot of sandboxing in this space though what do you mean?


Every Application should be it's own 'user' (sub user) while the login-user / manager should be the group leader of all those 'sub users' / 'agents'.

A change in security model from the 1970s/1980s might help with security and isolation. However that same security would also generally be a pain without really smooth management in the desktop environment / shell.


The Windows MSIX also does sandboxing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: