• Vendetta9076@sh.itjust.works
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    3
    ·
    19 hours ago

    I feel like when this pops up everyone freaks out and yells about how it’s proof the aur sucks and arch is doomed. Do you people randomly install GitHub repos without any due diligence? Do you click on random ads to download bake bean can cursors? There’s malware fuckin everywhere. Just do your due diligence and don’t get screwed. And if you do get malware, have a plan to make it irrelevant. Anyone who doesn’t do these things should in no way be using the AUR.

    • kylian0087@lemmy.dbzer0.com
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      1
      ·
      5 hours ago

      Arch as far as I am aware has never been recommended to new users. Sure their is CachyOS and other variants. And on top of that AUR you shut read the build scripts. But I suppose not many people do that unfortunately.

    • Sanctus@anarchist.nexus
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      1
      ·
      19 hours ago

      You have to go download an AUR helper to even get into the AUR, it does not come by default on Arch systems. You have to actually do this to yourself to get the malware.

        • LordKitsuna@lemmy.world
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          3
          Aquileo | arrow-down
          1
          ·
          1 day ago

          I’m very tired of the rhetoric that Arch is only meant for tinkerers. If all you do is have plasma steam and a web browser it’s no more or less likely to break than any other distro. You could go your entire life without ever looking at the terminal.

          And while yes this malware is a problem it is specifically in the aur, the arch user repository an unofficial repository not officially supported, just don’t use it. Unless you need a weird piece of software generally related to some type of specific hobby you’re unlikely to ever even want to look at it anyway.

          • bleustenns@lemmy.ml
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            1
            ·
            7 hours ago

            I do agree with this in theory. I just don’t know many ‘normal people’ that are going to only ever require those three things. (Totally with you on the AUR bit)

            • LordKitsuna@lemmy.world
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              1
              ·
              6 hours ago

              Really? If anything I have the opposite problem all the normal people I’m aware of probably don’t even need steam just the web browser and plasma. Pretty much everything is in the web browser these days I mean they might want the dedicated discord client but that’s ultimately just a web browser in a box and will also work perfectly no AUR required

    • thingsiplay@lemmy.ml
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      43
      Aquileo | arrow-down
      1
      ·
      3 days ago

      Adoption of unmaintained packages to maintain them is not a mistake. The problem is the current implementation, not the idea behind it. It’s like saying the AUR is a mistake, because some people do malicious stuff.

      They should find a better solution, like adoption shouldn’t be granted to everyone without question, especially new accounts who didn’t maintain anything before. Mass adoption shouldn’t be granted automatically (limit rate), in example 1 package adoption per day and if someone wants more, admins or moderators need to approve. And updates of newly adopted packages should wait a day.

      Also the AUR helpers should do a better job. Always ask if a new adopted package should be updated and give a warning the maintainer changed.

      • 𝘋𝘪𝘳𝘬@lemmy.ml
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        12
        ·
        3 days ago

        The problem is the current implementation

        Yes, exactly this! I am not surprised it happens. I’m surprised it didn’t happen before.

        especially new accounts

        Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

        Also the AUR helpers should do a better job.

        Even experienced people will just update as if nothing could happen. Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

        • thingsiplay@lemmy.ml
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          5
          ·
          3 days ago

          Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

          Which does not invalidate my point about new accounts, but yes. Its important for new accounts, so once a sleeper account is banned, its not that easy to just create thousands of new accounts while everyone is focusing on the current active ones. And if, as I suggested, mass adoption per account is not possible, then the attacker has less to attack.

          Edit: They need to make sure that sudden editing many packages in short time, with probably the same or similar lines should be automatically reported. They need some automated checks in place, at the very least. This would be a very suspicious behavior if many accounts are not active, and then suddenly all of them do something.

          Even experienced people will just update as if nothing could happen.

          Then you can’t fault the system, if you are this reckless.

          Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

          This would break all dependencies of this package. The point of adoption is to keep it working and stable. I’m highly against force changing the name, that is not a solution (at least not one I am happy about).

          • 𝘋𝘪𝘳𝘬@lemmy.ml
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            5
            ·
            3 days ago

            [Changing a package’s name] would break all dependencies of this package.

            Yes, that is correct. But that should not be a big deal for packages that are actively maintained. The maintainer can simply change the dependency to the new name after making sure the new package is legit.

            • thingsiplay@lemmy.ml
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              4
              ·
              3 days ago

              OK, that’s a good point. It would prevent auto updating. However any package that is NOT updated, should stay with same name in my opinion. So that everything (with the old secure code) stays intact and working. The name change should be part of the the update process. So it only breaks if you want to update, which would ensure compatibility if you choose not to (as it is safe). Something along the likes like this. I agree with your suggestion now, because that seems to be sensible idea.

      • lemmyvore@feddit.nl
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        4
        Aquileo | arrow-down
        4
        ·
        3 days ago

        They should find a better solution

        Who’s “they”? Because it’s not Arch. Arch doesn’t want to have anything to do with AUR, and neither does any of the Arch-derived distros. They’re all perfectly happy taking advantage of it, of course, but not the responsibility.

        • thingsiplay@lemmy.ml
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          10
          Aquileo | arrow-down
          1
          ·
          3 days ago

          Who’s “they”? Because it’s not Arch. Arch doesn’t want to have anything to do with AUR, and neither does any of the Arch-derived distros. They’re all perfectly happy taking advantage of it, of course, but not the responsibility.

          Where did you got this nonsense from? What do you mean “they are not Arch”? The AUR is managed and operated by the Archlinux team. As the packages are community-driven content, they cannot guarantee and give support, because it is not their package. But they are still managing and supporting the AUR itself.

          • lemmyvore@feddit.nl
            Aquileo | link
            Aquileo | fedilink
            English
            Aquileo | arrow-up
            2
            Aquileo | arrow-down
            11
            ·
            3 days ago

            And you’re gonna see the Arch team wash their hands of the whole thing, like they did in the past whenever the AUR was in trouble.

            That’s not real ownership.

              • lemmyvore@feddit.nl
                Aquileo | link
                Aquileo | fedilink
                English
                Aquileo | arrow-up
                2
                Aquileo | arrow-down
                6
                ·
                3 days ago

                Is the current state of the AUR, despite the previous waves of attacks, and its troubled history, not evidence enough? The Arch team has never made the AUR a priority and I don’t see why they would start now.

                The way I see it there are three possibilities:

                • They do nothing.
                • They shut it down.
                • They give it up for adoption.

                What is not going to happen is the Arch team putting time and effort into overhauling the AUR.

    • lemmyvore@feddit.nl
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      13
      ·
      3 days ago

      Remove unmaintained packages and block the name for several months.

      Alright, but that would mean most of AUR. Have a look at the package statistics box on the AUR homepage. Most packages fall under that definition in one way or another. The vast majority of the AUR is package some random person added once then never bothered with ever again.

      Frankly I’m surprised that the AUR has survived for so long in its current form, for what is basically a shell script distribution system with zero supervision and zero safety guards.

    • Tekdeb@lemmy.zip
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      12
      ·
      2 days ago

      Not if you follow the normal safety precautions for using the AUR. There are several things you can do to look for red flags, but the most essential thing is to read the PKGBUILDs. And helpers like yay, paru and Shelly can all show diffs which makes that much easier after the initial installation because in most cases you’ll just see that the version and checksum has changed which means it’s as trustworthy as last time.

      This has always been the case, and will continue to be the case unless the Arch team restricts the AUR which quickly can make it lose exactly what makes it so good.