"Potentially unsafe" label should be reserved for actual unsafe things

Yes it’s old news, but this decision still baffles me. It feels like self-sabotage for an app store to label 99% of its apps as unsafe, no other app store or repository has ever done this and for good reason.

It accomplishes two things: scares people and falls on deaf ears for others (if everything is unsafe, nothing is unsafe).

Even when the developer goes above and beyond with their safety practices, they only get “probably safe”. We don’t need this ambiguous unconfident threat level assessment at all, the page should tell users the permissions and details and let them figure it out, like with everything that isn’t on Flathub.

This label should be reserved for cases like these so it actually means something:

  • Apps using EOL runtimes
  • Apps that handle cryptocurrency keys (biggest fattest targets for hackers)
  • Abandoned networking apps
  • Unverified proprietary apps

This has been discussed multiple times in the forum and a Google search brings up a lot of old threads like Framing of "unsafe" permissions scares off non-technincal users

There’s also an open issue in the website repository about this. There isn’t any need to open new topics for general disagreements about the labelling.

We are aware that the labelling is overzealous but a lot of it is about what a permission theoretically allows to do and not what an application in the sandbox actually does in practice.