this post was submitted on 24 Mar 2026
42 points (95.7% liked)

linux4noobs

4035 readers
69 users here now

linux4noobs


Noob Friendly, Expert Enabling

Whether you're a seasoned pro or the noobiest of noobs, you've found the right place for Linux support and information. With a dedication to supporting free and open source software, this community aims to ensure Linux fits your needs and works for you. From troubleshooting to tutorials, practical tips, news and more, all aspects of Linux are warmly welcomed. Join a community of like-minded enthusiasts and professionals driving Linux's ongoing evolution.


Seeking Support?

Community Rules

founded 2 years ago
MODERATORS
 

Obviously this is somewhat subjective, but I've had a lot of problems in my previous attempts to switch to Linux, so I'd like to create a list of distros to try out, and see what works for me. I'm mostly expecting to be doing basic office work and light gaming via Steam.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] pmk@piefed.ca 1 points 1 day ago (1 children)

With the criteria flathub uses for verification, everything in debians own repos is unverified. We're trusting the maintainer either way.

[โ€“] ProdigalFrog@slrpnk.net 1 points 1 day ago* (last edited 1 day ago)

To become a debian maintainer, you need to have already built up a rapport with Debian by being a sponsored maintainer, which lets you submit packages, but they must be approved by your sponsor. Only after establishing and proving yourself can you become a full Debian package maintainer, which also requires a trusted Debian team member advocates for you to become one based on your previous work in detail. While not impervious to bad actors, this structure creates a pretty solid level of trust in the Debian repos.

In contrast, anyone can create and submit a Flatpak to Flathub, only needing to pass a volunteer review process. Critically, after an app passes the first volunteer review process, the submitter can then push updates to the flatpak without review, meaning they could initially upload a clean version of an app, then push a version with malware in an update. Personally I don't think that security model is as effective at preventing malware compared to the Debian model of slowly building trust before being given the keys.

Verified flatpaks, on the other hand, require the submitter to verify they are part of the dev team for that application to the Flathub team, which makes them pretty much as trustable as any Debian repo package, which make them a good, safe default to show for an appstore (IMO).