The Reg FOSS desk takes an extremely jaundiced view of this.
The Reg FOSS desk is not the only one. Don't touch 'em and you'll never be scammed.
After multiple waves of cryptocurrency credential-stealing apps were uploaded to the Snap store, Canonical is changing its policies. In what's expected to be a temporary measure, an announcement on the Snapcraft Discourse says that the Ubuntu vendor will switch to manual review of all new snap name registrations. The post from …
It amazes me that people commenting on this topic focus on scammed person being bitcoin user and not on who is responsible for this problem (which is Canonical)
> Part of the problem is that these apps look legitimate to casual inspection because the Snap Store badges them as "safe."
Let people use whatever they like on their PCs. And let them be sure that whatever they use, it comes from legitimate source.
In a way I really wish that they would stop extending it because every time this happens it allows my lords and masters to de-prioritise the urgent upgrades due to EoSL or the end of ESM and return to their favourite pastime of kicking the can down the road.
Wait, so any old ne'er-do-well can just upload any old malware to the snap repository? «rolls eyes»
That's yet another point in favour of the traditional Debian (and derivatives) repo system, then, where package maintainers have to earn trust and be approved before packages can be approved, and there is (hopefully) more than one trusted person looking at changes to each package.
That "move fast and break things" meme yet again proving that the second part needs to be highlighted much more than the first…
Last time, there was a temporary restriction on new uploaders, then the restriction was lifted with (apparently) no further controls in place...so the cycle repeated.
There are several steps that could be taken to improve the situation - like forcing user visibility to the app's manifest in the store, like Flathub - that wouldn't require incremental review time by the Canonical/Snapcraft team for each new app.
My fear is that it'll simply be another "wait out the storm" situation, and that next time, the malicious apps might be in a category that's not quite so easily dismissed as crypto.
... which is reliable and peer-reviewed software repos.
This is what I loved in Ubuntu, that I could just set up server just using APT and I could be pretty sure that nothing I've installed is malware and won't do any greater damage. And the software I'm installing is indeed the software I was thinking about, not just similarly named scam. And now Canonical brings Snaps and ruin that all.
It’s not Snaps as a containerized framework that is the problem, seeing as how it is head and shoulders ahead of Flatpak and the laughable App Image in production, manageability and security, but Canonical not yet realizing they have become the Google or Apple of Linux world in Snaps creation and in a Snap Store. They need to quickly and competently scale up their inspection, verification and certification department to the order of a Google or better yet Apple.