Patreon Logo Support us on Patreon to keep GamingOnLinux alive. This ensures all of our main content remains free for everyone. Just good, fresh content! Alternatively, you can donate through PayPal Logo PayPal. You can also buy games using our partner links for GOG and Humble Store.
Title: Security feature dreaming.
LoudTechie 2 years 10 hours ago
In a flatpak discussion I started thinking about security features for packages.
I realized there's actually a Windows security feature I would love to see expanded in Linux. Especially for proprietary packages.
Rep building. The "cheap" executable signing certificates require first a few thousands accepts before stopping to generate warnings.

We already have this somewhat with testing repos, but I would love to see this expanded into flatpak and maybe even something tailored for it.
Something like a torrent based package manager where you normally install things via GUI, but if it doesn't have enough peers yet only through the CLI with a special flag that when provided is only able to install packages with few peers.
So install without flag: only peer rich packages.
Install with flag: only peer poor packages.
It doesn't have to be peers. It could be any form of traceable recommendation, such as signed hashes.
You could even build a more complicated system rep building, with certain peers carrying more weight than others if they for example run comparable packages.

Someone with commentary on this brainfart?
New LoudTechie 2 years 10 hours ago
Quoting: LoudTechieIn a flatpak discussion I started thinking about security features for packages.
I realized there's actually a Windows security feature I would love to see expanded in Linux. Especially for proprietary packages.
Rep building. The "cheap" executable signing certificates require first a few thousands accepts before stopping to generate warnings.

We already have this somewhat with testing repos, but I would love to see this expanded into flatpak and maybe even something tailored for it.
Something like a torrent based package manager where you normally install things via GUI, but if it doesn't have enough peers yet only through the CLI with a special flag that when provided is only able to install packages with few peers.
So install without flag: only peer rich packages.
Install with flag: only peer poor packages.
It doesn't have to be peers. It could be any form of traceable recommendation, such as signed hashes.
You could even build a more complicated system rep building, with certain peers carrying more weight than others if they for example run comparable packages.

Someone with commentary on this brainfart?
We could even adapt the pricing in a FOSS way.
repbuilding: containerized proprietary packages
Non-repbuilding: containerized reproducible builds, with the source code and license(FOSSness can as such be automatically checked by building it and hash-checking)
Non-repbuilding with root: distro packages

For reference the Windows scheme is:
repbuilding: 215.99$/yr and strict signature management rules.
non-repbuilding: 279.99$/yr and very very strict signature management rules.
Root: 500$/yr, Microsoft gets to read your code and has to sign off each update.
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon Logo Patreon. Plain Donations: PayPal Logo PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register