Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Gentoo is supporting officially Snap packages?
Date: Thu, 16 Jun 2016 17:58:58
Message-Id: 5762E8D6.5040109@gmail.com
In Reply to: [gentoo-user] Re: Gentoo is supporting officially Snap packages? by James
1 James wrote:
2 > José Maldonado <josemald89 <at> gmail.com> writes:
3 >
4 >
5 >> The last days, ArsTechnica publish this new:
6 > http://arstechnica.com/information-technology/2016/06/goodbye-apt-and-yum-ubuntus-snap-apps-are-coming-to-distros-everywhere/
7 >> "Snaps now work natively on Arch, Debian, Fedora, Kubuntu, Lubuntu,
8 >> Ubuntu GNOME, Ubuntu Kylin, Ubuntu MATE, Ubuntu Unity, and Xubuntu,"
9 >> Canonical's announcement says. "They are currently being validated on
10 >> CentOS, Elementary, Gentoo, Mint, OpenSUSE, OpenWrt and RHEL, and are
11 >> easy to enable on other Linux distributions." (Ubuntu will continue to
12 >> support deb packages, but developers can choose to package applications
13 >> as snaps instead of or in addition to debs.)"
14 >>
15 >> Gentoo is supporting officially Snap packages? Why not Flatpak?
16 >>
17 >> Thank you very much for your responses! Bye! :)
18 >>
19 >
20 > One word SECURITY? Trust but verify does come to mind.
21 >
22 > Containers are not exactly the most secure apparatus, imho.
23 > "Clair is an open source project for the static analysis of vulnerabilities
24 > in appc and docker containers." [1]. So, I want to hear about the robustness
25 > of the security on these 'self containerd packages.
26 > What exactly creates the codes necessary for the container ?
27 >
28 > Is their a version that works on gentoo-hardened?
29 >
30 > Suggestions for firewalling off a system for routine, deep examination
31 > and profiling of port activities, would be most welcome. Prima facia,
32 > I just have no trust in wonderful ideas from the *buntu crowd, ymmv.
33 >
34 > Also, it's a really good idea; now maybe *DALE* can get his security
35 > VM, in a snap (snapple?, snapit?, snapper?), that is gentoo-hardened
36 > blessed? Maybe the snhap designation for secured (Hardeded) snaps?
37 > Maybe if it's a hardened, entertainment (video snap) we call them schnapps?
38 >
39 > I've been bantering about for a couple of years now how clusters (hpc and
40 > containers) are going to change everything. Security is the main obstacle
41 > now. You know, I'm ready to sip this Kool_aid and ponder the possibilities....
42 >
43 > Were are all the security gurus on at on snaps? Do snaps require systemd
44 > or are they PID-1 agnostic?
45 >
46 >
47 >
48 > James
49 >
50 >
51 >
52 >
53 >
54 > [1] https://github.com/coreos/clair
55
56
57 I saw this and was curious as well. I'm needing to google a bit on just
58 what this is about. Given the name, it should be interesting. I
59 suspect I'll get a lot of hits about a energy drink thingy. lol Oh,
60 and this thread too. ;-)
61
62 Dale
63
64 :-) :-)