Flatpak gets 508,640 euros for better Linux security
A video player should in the future be able to play music through the speakers without simultaneously opening the microphone. This separation is one of the goals of a new Flatpak project funded with 508,640 euros by the Sovereign Tech Agency. Modal Collective is coordinating the work, with Para-Real Ltd. providing organizational support; according to the current plan, it is scheduled to run through the end of 2027.
Flatpak distributes Linux desktop applications in a sandbox, meaning they are largely isolated from the rest of the system. Portals serve as the controlled door to the outside: An application requests a clearly defined permission, and the portal can restrict access or require user confirmation. New portals are intended to divide this access more precisely for audio, the microphone, networks and VPNs.
For audio, new socket permissions for PipeWire, rules in WirePlumber and a dedicated audio portal are planned. For networking, there are to be separate static permissions for the host computer, the local network, the internet and specific ports. A VPN portal could allow third-party apps to manage connections at the system level without leaving the sandbox or receiving broad host permissions.
The list also includes a spell-checking portal and foundational work on password autofill. This is intended to replace existing Native Messaging mechanisms through which, for example, browser extensions communicate with locally installed password managers. An entitlement system could also make it clear why an application needs specific portal permissions.
And then, concretely? Users of Fedora Silverblue and SteamOS, as well as Debian and Mint, could in the future use more features without granting applications blanket access to devices and networks. That would be a security benefit in everyday use, provided the planned interfaces are actually implemented. That has not happened yet: The roadmap may change, and Modal still sees Flatpak as lagging behind Android and iOS in security and sandboxing features. The funding is therefore also intended to supplement limited maintainer capacity with lasting expertise and more reliable structures.
Comments
Loading the thread…
Sign in to leave a comment. Sign in