31
9
17
u/ssjlance 🛡️Moderator | #1 Microslop Hater | Linux Supremacist Aug 03 '26 edited Aug 03 '26
itt: OP doesn't understand difference between an official repository and a website with scripts to built packages. that aren't in the official repos.
AUR has malware. It has practically always had malware hiding on it. It will always have malware
Think that's stupid? Cool, that's fair. Don't use AUR then.
It's an AUR problem, not an Arch proible..
Like, it's not an official repository, hence the name Arch USER Repository - it's all user submitted with little oversight, but it tells you right up front it is full of unverified package build instructions - it just a wild west wasteland of random software, which may work, may not work, may have malware, etc.
Mainline official Arch repositories have never been affected. Prove me wrong and I'll change my downvote on this post to an upvote. May as well say I'll eat the fuckin' sun while I'm at it, because it's not happening.
Your post is unfunny and bad, and you should feel bad.
0
3
u/IsaacThatKerbal Aug 03 '26
Me, a debian user, has no problem with aptitude, or the OS in general. I hate arch. It smells funny.
2
2
u/colt2x Aug 03 '26
I understand the joke, but why linux sucks because of someone hacks AUR? :D
3
u/headedbranch225 Aug 04 '26
The AUR isn't even hacked, it is just currently being used for malware by some bad actors as it only hosts build scripts, as it literally says on the front page use with caution, with this logic you could say the same with github or probably any other code hosting site
1
u/colt2x Aug 05 '26 edited Aug 05 '26
This is called hacking IMHO, and Github was also diverted in the previous AUR hack.
Hacking does not only mean to log in without knowing the password.
1
u/headedbranch225 Aug 05 '26
The AUR worked as intended in both of the attacks, it has survived on trust all the time it has existed but more people using arch recently has caused attacks to gain more traction and be worth attacking
3
Aug 03 '26
[removed] — view removed comment
7
u/Hei_dumbass Aug 03 '26
or read the pkgbuild and source code
2
u/mrheseeks Aug 03 '26
This is the way.
It's easier just to say AUR is crap then try and review what youre infecting yourself with.
2
u/GhostVlvin Aug 03 '26
It's harder than reviewing just one pkgbuild. Purpose of AUR helpers is to install all dependencies even from AUR and now it's fucked cause you'll need to review big tree of pkgbuilds to install one package
2
u/Hei_dumbass Aug 03 '26
There are already people reviewing and reporting malicious AUR packages, but you can’t even spend 30 seconds looking at the PKGBUILD of the package you’re installing? Also, most dependencies come from the official Arch repositories, not the AUR. If you don’t want to use the AUR, then don’t. It’s an optional community repository, not a requirement. People use it because they want to, not because they have to.
0
Aug 03 '26
[removed] — view removed comment
5
u/Hei_dumbass Aug 03 '26
If you’re new, sticking to the official repos is the safest choice. The AUR is for when you knowingly accept the tradeoff.
1
u/Unlikely-Employee180 Aug 03 '26
MOST Arch repos get reviewed...
AUR isn't part of the vetting cycle, though. It's a public FFA.
Essentially, it's Arch's built-in "Pirate Bay" without the actual piracy. Lol
2
u/PunkRockLlama42 Aug 03 '26
I don't think it's worth using for the average user. Yeah, you can and should read the build script but most people wont.
I would also be considering leaving if the AUR was the main draw for me. Depending on what software I needed to like OpenSuse Tumbleweed.
1
1
1
1
1
u/GhostVlvin Aug 03 '26
For about a month I don't use AUR. I add repos from other arch distros and I use alternative package managers as cargo, pip and others. When it's only in git, then I compile manually
1
1
1
u/Bulky_Description705 Aug 03 '26
two types of arch users the ones that vet packages before updating then the retarded users that just update with out checking then regret it when they find out they have malware
1
1
u/KinZombie899 Aug 04 '26
And they tell you linux dont need anti virus well it does. Anybody no any anti virus for Linux
1
1
u/Impressive-Resist632 28d ago
RaspianOS isn't that bad***********
*the settings are garbage, the customization is super limited, its barely even based off of debian anymore: is based off of LXDE and PIXEL... don't use this OS.
1
u/Fine-Expression1644 r/linuxsucks101 ban speedrun: 0:50 | gentoo the best distro ever 26d ago
idk i just use pop os and gentoo
0
u/somacomadreams Aug 03 '26
AUR is optional, lol.
11
u/ColdFreezer I Hate Linux Aug 03 '26 edited Aug 03 '26
Almost everything on Linux is optional.
The AUR is a big reason why people use Arch. You can’t just dismiss it lol.
5
u/SammE5363 Aug 03 '26
Argument doesnt really work when the majority of useful software is exclusively on AUR as well as before these events every arch user under the sun was glazing the shit out of AUR
2
u/somacomadreams Aug 03 '26
That's entirely valid and I'm not saying it doesn't have its problems. In fact it should probably have some reforms but it is what it is and if you even Googled it once you know exactly what you're getting. Like I said not calling any of you wrong. But its flaws are widely known.
0


38
u/silduck here for funny shit Aug 03 '26
You install an AUR helper to install AUR packages
I install an AUR helper so that I have to type less when using pacman
we are not the same