With all the supply chain attacks in the Linux ecosystem, isn’t the natural solution to move to full application sandboxing?

Flatpacking is great but not all applications support it.

Is it too much of a hassle?

  • SleepyPie@lemmy.worldOP
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    edit-2
    1 day ago

    Am I naive to think that Qubes would be less work?

    I’d set up a few different qubes for the apps kind of like graphene and then just let them update as normal. If I hear anything bad about them I just nuke that qube right?

    A little extra up front work, but way easier to maintain with much less at risk if something goes wrong?