1 |
James wrote: |
2 |
> José Maldonado <josemald89 <at> gmail.com> writes: |
3 |
> |
4 |
> |
5 |
>> The last days, ArsTechnica publish this new: |
6 |
> http://arstechnica.com/information-technology/2016/06/goodbye-apt-and-yum-ubuntus-snap-apps-are-coming-to-distros-everywhere/ |
7 |
>> "Snaps now work natively on Arch, Debian, Fedora, Kubuntu, Lubuntu, |
8 |
>> Ubuntu GNOME, Ubuntu Kylin, Ubuntu MATE, Ubuntu Unity, and Xubuntu," |
9 |
>> Canonical's announcement says. "They are currently being validated on |
10 |
>> CentOS, Elementary, Gentoo, Mint, OpenSUSE, OpenWrt and RHEL, and are |
11 |
>> easy to enable on other Linux distributions." (Ubuntu will continue to |
12 |
>> support deb packages, but developers can choose to package applications |
13 |
>> as snaps instead of or in addition to debs.)" |
14 |
>> |
15 |
>> Gentoo is supporting officially Snap packages? Why not Flatpak? |
16 |
>> |
17 |
>> Thank you very much for your responses! Bye! :) |
18 |
>> |
19 |
> |
20 |
> One word SECURITY? Trust but verify does come to mind. |
21 |
> |
22 |
> Containers are not exactly the most secure apparatus, imho. |
23 |
> "Clair is an open source project for the static analysis of vulnerabilities |
24 |
> in appc and docker containers." [1]. So, I want to hear about the robustness |
25 |
> of the security on these 'self containerd packages. |
26 |
> What exactly creates the codes necessary for the container ? |
27 |
> |
28 |
> Is their a version that works on gentoo-hardened? |
29 |
> |
30 |
> Suggestions for firewalling off a system for routine, deep examination |
31 |
> and profiling of port activities, would be most welcome. Prima facia, |
32 |
> I just have no trust in wonderful ideas from the *buntu crowd, ymmv. |
33 |
> |
34 |
> Also, it's a really good idea; now maybe *DALE* can get his security |
35 |
> VM, in a snap (snapple?, snapit?, snapper?), that is gentoo-hardened |
36 |
> blessed? Maybe the snhap designation for secured (Hardeded) snaps? |
37 |
> Maybe if it's a hardened, entertainment (video snap) we call them schnapps? |
38 |
> |
39 |
> I've been bantering about for a couple of years now how clusters (hpc and |
40 |
> containers) are going to change everything. Security is the main obstacle |
41 |
> now. You know, I'm ready to sip this Kool_aid and ponder the possibilities.... |
42 |
> |
43 |
> Were are all the security gurus on at on snaps? Do snaps require systemd |
44 |
> or are they PID-1 agnostic? |
45 |
> |
46 |
> |
47 |
> |
48 |
> James |
49 |
> |
50 |
> |
51 |
> |
52 |
> |
53 |
> |
54 |
> [1] https://github.com/coreos/clair |
55 |
|
56 |
|
57 |
I saw this and was curious as well. I'm needing to google a bit on just |
58 |
what this is about. Given the name, it should be interesting. I |
59 |
suspect I'll get a lot of hits about a energy drink thingy. lol Oh, |
60 |
and this thread too. ;-) |
61 |
|
62 |
Dale |
63 |
|
64 |
:-) :-) |