TLDR: Open package repositories without some approval and oversight system, like AUR, will have even more problems in the future due to advanced coding AI and malicious
foreignhackers.Edit: Please normalize TLDR’s on bot posts with just a link.
Edit 2: I have been rightfully informed that this is not a bot post. I still think links should not be posted without a tiny abstract, one might say: a TLDR.
I have also been informed that the text does not spell out “foreign”. This is correct. The text does say
Not all of the packaging issues are as bad as the initial wave of trying to steal credentials, some are just adding ridiculous messages in Russian.
This implies but does not establish the nationality of attackers. While Arch has contributors from all over the world, it is commonly cited as being a Canadian distribution (example, see below). https://distrowatch.com/table-mobile.php?distribution=arch
“Foreign hackers”
Foreign to who?
The article never said “foreign”, you made that up.
I guess if youre not from the US theyre “foreign”
OP is not a bot
Then they should’ve included a short TLDR even harder
No, normalize forcing users to click the link and read the full text.
AUR is still working as intended. It’s basically a public wiki of shell scripts, it was never intended to be secure in the first place. It has always been the user’s responsibility to review everything or avoid using it.
The command
pacman -Qmwill display every package from the AUR on your system. You can then search the list of compromised packages.Here are some scripts that can help too
(Edit: apparently i need to say to read and understand what these scripts are doing before running them. If you don’t understand what you’re running then don’t run them) https://gist.github.com/Kidev/85756c3dcad3623ca5604a8135bafd14
At least some level of human review is going to be needed.
So… completely negating the point of a User Repository??? Introduce some kind of authoritative oversight, and it’s essentially just another regular repository, erasing all the benefits of the AUR. The whole point of the distro slapping a huge disclaimer of “DISCLAIMER: AUR packages are user produced content. Any use of the provided files is at your own risk.” at the top of the homepage is because these kind of compromises are the trade-off one makes
I think I’d be satisfied with just not allowing people to take over orphaned packages. That seems like a glaring attack vector and closing it would not harm the AUR in any way.
And yea, arch (and its derivatives) probably should not ship with AUR helpers pre-installed.
arch doesn’t ship an aur helper pre installed. It’s the derivates leeching the arch aur infrastructure and preinstalling aur helpers suggesting it’s safe to use as is
Thanks for the clarification. I am relatively new to arch.
AUR has never been a good idea. I don’t use it and this news proved me right.
Does that mean a distro official package manager would be immune to infections? Of course not, but they do offer a more secure distribution system and build greater trust. Minimizing the chance of malware being spread through their means.
Edit: If you have the knowledge and time to inspect the AUR packages you install, AUR might be good for you. I have none of these, that’s why I stick to my official distro packages (and sometimes also some flatpak but from official sources)
Me, a Debian user, watching that shitshow 😎
Debian users should receive their news 6-12 months after everyone else, change my mind
/s
Some people likes tested and stable software. It’s weird.
That’s optimistically quick
Sincerely,
A Debian user
Huh, you really feel schadenfreude over another reputable project being hit by/having to deal with malware? And all the people who might be affected by it?
That is not something that would ever cross my mind.
I mean, but this is arch.
And?
Whoa, this is blowing up. Chill, guys. I really think that sucks. If anything, with Arch being bleeding edge and all of that, at least you’re showing early the tough wake up the other distros will have to do in relation to malware after Linux’ increasing popularity. Time to brush those SELinux and apparmor bits, even.
But, now, we Debian users are okay, (btw, 😎).
Me, a NixOS user, watching folks fighting over a bunch of legacy distros 😎😎😎
Now’s our chance, it’s time for a hostile takeover from my fellow "i use nix btw"s!
I am actually enjoying most of it, yeah.
But why? Arch isn’t a server distro and their users usually know how to keep their secrets save. A FUD campaign?
Where at “I use Arch btw” now?
Is the Chaotic-AUR a viable alternative? As I understand, there is some level of review.











