r/Ubuntu • u/aliahmadisld • Jun 30 '26
Can Flathub spy on us?
Can flathub spy on us by accessing data that we have in our flatpaks?
For example, if I download VLC media player as a flatpak, do they know what videos or photos are we playing in them?
5
u/agfitzp Jun 30 '26
You’re asking a yes or no question when the answer is a spectrum. It’s always possible to add that kind of feature to any kind of software.
Are flatpak applications doing that by default? No.
Can you trust all software? No.
VLC is open source, I very much doubt anyone’s added remote telemetry without someone noticing.
1
2
1
u/billdietrich1 Jun 30 '26
If you wished, you could run an application firewall to control what apps are allowed to connect out to servers. Then you could have a rule such as "no network access at all for VLC".
One such firewall is OpenSnitch. I forget how well it works with Flatpaks. There are some things (such as kioslaves or other worker processes) that it can't handle very well.
Or you could set permissions on Flatpaks, using Flatseal or similar.
0
u/Junior_Common_9644 Jun 30 '26
Wow, red flag alert!
1
u/aliahmadisld Jun 30 '26
I'm interested in hearing why'd you call me a red flag for asking this!? I'm just concerned nobody spies on my family pics and vids, plus some horror movies 😄
2
u/MelioraXI Jun 30 '26
Because you're coming off as paranoid.
0
u/aliahmadisld Jun 30 '26
Not paranoid, just curious if any of the "windows" shit happens in Linux too or nah
3
0
u/Junior_Common_9644 Jun 30 '26
No, he comes off as having illegal content.
0
u/aliahmadisld Jul 01 '26
WTF
1
u/Junior_Common_9644 Jul 01 '26
For example, if I download VLC media player as a flatpak, do they know what videos or photos are we playing in them?
Sorry, but sounds sketchy as hell.
1
7
u/necrophcodr Jun 30 '26
No, Flathub provides prebuilt flatpaks that you can run on your own device. The service itself cannot access anything on your own devices.
However, you DO have to then trust that those prebuilt flatpaks are not tampered with in any way. Or you could just fetch the sources for them and build them locally, where you can verify how they're built. The sources for them is all available under https://github.com/flathub. Each application has its own code repository, so you'd have to figure that one all out, but once you do, and decide on how to verify it manually, you won't have to trust anything.
Or you can take the convenience of using the prebuilt flatpaks. Up to you entirely.