Ubuntu 16.04 Snap package security issues

Source: Internet
Author: User

Ubuntu 16.04 Snap package security issues

The Snap package is a new software packaging method introduced by Ubuntu 16.04. Canonical claims that it is a secure software development method that prevents applications from stealing system data. Olli Ries, product director of the Ubuntu client platform, also pointed out that the Snap security mechanism can isolate applications from the system, when installing a Snap package, you do not have to worry about whether it will affect other applications or systems.

However, Matthew Garret, a well-known Linux kernel Development and Security Developer of CoreOS, believes that Canonical is only half right. It points out that: the Snap package does provide real security improvements on Ubuntu mobile devices, which is totally misleading to Ubuntu Desktop Users. The private data can be copied using the Snap package installed by the user. To prove his point of view, Matthew Garnett created a conceptual attack Snap package to prove its effectiveness and successfully stole the SSH private key. It mentioned that the key to successful theft is that the Ubuntu Desktop version uses X11 windows to provide only a small amount of security. As long as the Ubuntu Desktop System still uses X11, Snap cannot provide sufficient security protection.

Address: http://www.sysgeek.cn/ubuntu-16-04-snap-format-security-risk/

Address: http://www.linuxprobe.com

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.