Ubuntu 16.04 Snap package security issues
The Snap package is a new software packaging method introduced by Ubuntu 16.04. Canonical claims that it is a secure software development method that prevents applications from stealing system data. Olli Ries, product director of the Ubuntu client platform, also pointed out that the Snap security mechanism can isolate applications from the system, when installing a Snap package, you do not have to worry about whether it will affect other applications or systems.
However, Matthew Garret, a well-known Linux kernel Development and Security Developer of CoreOS, believes that Canonical is only half right. It points out that: the Snap package does provide real security improvements on Ubuntu mobile devices, which is totally misleading to Ubuntu Desktop Users. The private data can be copied using the Snap package installed by the user. To prove his point of view, Matthew Garnett created a conceptual attack Snap package to prove its effectiveness and successfully stole the SSH private key. It mentioned that the key to successful theft is that the Ubuntu Desktop version uses X11 windows to provide only a small amount of security. As long as the Ubuntu Desktop System still uses X11, Snap cannot provide sufficient security protection.
Address: http://www.sysgeek.cn/ubuntu-16-04-snap-format-security-risk/
Address: http://www.linuxprobe.com