Thats a fair point. But the real and simple problem is "your phone number was breached somewhere, change it". I never get spam calls or mails, people that are not careful do.
Probably, but I guess thats the lack of "it has to be updated". Just as distro maintainers do, flatpak maintainers or contributors can do as well, as its often pretty easy.
KDE has flatpak settings included, GNOME is doing their thing with unix philosophy and all. Flatseal works fine.
As I said, you should not need to edit those settings, maybe you need to, and if it generally makes sense (for example GNUmeric only has documents access, nothing else) this needs to be fixed.
For editing desktop entries, copy it fron this strange directory ~/.local/share/flatpak/exports/share/applications/ to your normal ~/.local/share/applications which will always override the others.
if you want to change app permissions, use Flatseal and add the needed directory. This is very easy. If it is something all users generally need, open a bug on their repo.
Not sure what that means, but probably native messaging, a biig missing portal.
Flatpak has an Inter-process-communication permission, so software could absolutely be opt-in allowed to talk, while keeping security for the rest. Apps cant see each others ~/.var/app/org.app.name/ storage though, never.
Thats a fair point. But the real and simple problem is "your phone number was breached somewhere, change it". I never get spam calls or mails, people that are not careful do.