Skip to content

Instantly share code, notes, and snippets.

@aral
Last active December 12, 2021 15:33
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save aral/5b283d020bab878ca8b2cc83bc66b88d to your computer and use it in GitHub Desktop.
Save aral/5b283d020bab878ca8b2cc83bc66b88d to your computer and use it in GitHub Desktop.

elementary OS 6 AppCenter App Permissions Review

Work-in-progress: A brief security review of permissions of curated apps on the elementary OS 6 AppCenter (see elementary/appcenter#1012 and elementary/appcenter-reviews#225 for context).

Unsandboxed apps

These are apps with --filesystem=home or above permissions that currently should not be allowed on the AppCenter (as per elementary/appcenter-reviews#225)

AppCenter top carousel

Accessories

I’ve only looked through the paid apps on the accessories section and it is clear that non-sandboxed apps have been allowed on the AppCenter.

We need a clear policy on this going forward.

Apps with broken links

  • ScreenRec (featured in top carousel in AppCenter): https://github.com/dr_styki/ScreenRec is 404 (as are issues and help links). This essentially means this is a closed-source app on the AppCenter. I cannot verify what permissions it has or what it does.
  • Homepage link on LookBook leads to danielfore.com which appears to have been taken over by a link farm. At least on one load, uBlock origin blocked the domain as known malware was being served from it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment