Activity log for bug #1887204

Date Who What changed Old value New value Message
2020-07-10 22:51:11 Merlijn Sebrechts bug added bug
2020-07-10 22:51:28 Merlijn Sebrechts information type Private Security Public Security
2020-07-10 22:59:00 Merlijn Sebrechts description Snap does not clearly communicate to users about partial strict confinement. It should do so at multiple places: * Installing a classic confined app results in an error message in the CLI and a warning in the Snap Store. Installing a strictly confined app on a distro which has partial support for this has similar security and privacy issues, but the user is not notified about this. * The documentation about the benefits of confinement does not talk about partial strict confinement and there is not list about which distro's support strict and partial confinement. This leads to dangerous situations where users think an app is restricted, but it isn't. WPS office is a common example for this. The snap store has multiple versions of WPS office with network access disabled because users might be worried about sensitive documents leaking to the internet. source: https://forum.snapcraft.io/t/how-are-snaps-claiming-to-have-no-internet-plug-regulated/18755/22 Snap does not clearly communicate to users about partial strict confinement on distributions which do not support all required confinement features. It should do so at multiple places: * Installing a classic confined app results in an error message in the CLI and a warning in the Snap Store. Installing a strictly confined app on a distro which has partial support for this has similar security and privacy issues, but the user is not notified about this. * The documentation about the benefits of confinement does not talk about partial strict confinement and there is not list about which distro's support strict and partial confinement. This leads to dangerous situations where users think an app is restricted, but it isn't. WPS office is a common example for this. The snap store has multiple versions of WPS office with network access disabled because users might be worried about sensitive documents leaking to the internet. source: https://forum.snapcraft.io/t/how-are-snaps-claiming-to-have-no-internet-plug-regulated/18755/22
2020-07-13 07:05:42 Maciej Borzecki snappy: status New Confirmed
2023-09-20 13:19:55 Michael Vogt affects snappy snapd
2023-11-22 13:38:03 Kaan Batın Kolcu bug added subscriber Kaan Batın Kolcu