Hey all!

(I did post this in c/flatpak, but this community is more active. I am not sure where would be more appropriate)

Something that I have been wanting to get working is having my browser and password manager both in flatpak. I really like being sandbox and having faster updates if the distro is on the slower side perhaps.

I have a set up with Firefox as a deb and keepassxc as a flat and that works find as one would expect. I did want to install Vivaldi as a flatpak and was not able to get it to talk with keepass.

In my reading I found this: installing KeePassXC natively, which you’d actually want for security reasons.

installing KeePassXC natively, which you’d actually want for security reasons

What is mean by that line of reasoning?

  • ozymandias117@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    5 months ago

    They’re saying that it only works if your browser is installed natively and your password manager is sandboxed, which is the exact opposite of what you’d want

    The browser is the vulnerable software that needs sandboxing

    Both being sandboxed would be fine, too

    • InternetCitizen2@lemmy.worldOP
      link
      fedilink
      arrow-up
      2
      ·
      5 months ago

      Perhaps. In my distro of choice (popOS) the flatpak is a bit ahead of the repo version. I feel that having the bug fixes and only being able to interact with keepass via the sandbox would limit the attacks. I am not an expert on security, so i would like to hear where my current ideas fail.

  • thayer@lemmy.ca
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    5 months ago

    I run the flatpak versions of KeepassXC and Firefox. In order to enable auto-type, I disable Wayland for both apps via Flatseal (enabling fallback to X11). Works fine in KDE and GNOME, though GNOME now prompts to share the display once per session…something to do with how the portals work now.

    • federalreverse-old@feddit.de
      link
      fedilink
      arrow-up
      6
      ·
      5 months ago

      X11 is not made with security in mind. At the point where you disable Wayland, you can basically use native apps rather than flatpaked apps.

      • thayer@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        5 months ago

        Oh I’m well aware of X11’s shortcomings, and it’s a band-aid fix until Wayland and/or the DEs sort these capabilities out. If that day doesn’t come within the next year or so, I’ll consider other options then.

  • boredsquirrel@slrpnk.net
    link
    fedilink
    arrow-up
    2
    ·
    5 months ago

    works fine as one would expect. Not that self explanatory, I wonder how

    install Vivaldi as a flatpak and was not able to get it to talk with keepass.

    No the native messaging portal is missing

    What is mean by that line of reasoning?

    Makes no sense. The Flatpak is official and more isolated than native packages. Reduce the number of system apps as much as possible.

    See my thread on the methods but they are all hacky. You could copy the KeepassXC binary to the Browser flatpak container and launch it from there. But this needs to be repeated on every update, but it is possible and can be automated.