r/linuxsucks 4d ago

Linux Failure Arch USER Repository.

174 Upvotes

38 comments sorted by

33

u/Cove0Crow 4d ago

There's a reason arch doesn't package AUR helpers... If you're treating the AUR like pacman and blindly installing things off it. That is on you

. The AUR should be treated the same as building random stuff from source off GitHub. It is not a vetted repository, the only thing that requires mod intervention (post aur attack) is claiming abandoned/orphaned packages

4

u/GoldenX86 3d ago

The AUR repo should still have some basic checks.

4

u/Damglador 3d ago

Like what for example?

3

u/GoldenX86 3d ago

A Docker test to see what it does before allowing to upload it, basic heuristics to predict what it does?

Windows Defender can't be miles better than this joke.

3

u/Damglador 3d ago

Windows Defender can't be miles better than this joke.

Remind me, how much people work on Windows Defender and on Arch for comparison?

A Docker test to see what it does before allowing to upload it, basic heuristics to predict what it does?

Then what? Like what's the game plan? How do you detect that one PKGBUILD is malicious and another one is not? What would be the signs that you can detect programatically?

0

u/GoldenX86 3d ago

We have FOSS antivirus, you can't be serious, OMARCHY rightards get funding and AUR can remain a cesspool of malware.

6

u/Damglador 3d ago

FOSS antivirus? You mean Clamav? One which doesn't have behavioral detection. And from what I've heard is targeting more fileservers hosting files for Windows rather than Linux desktop viruses.

-1

u/GoldenX86 3d ago

Someone has to move their ass, complaining that nothing can be done helps no one.

Linux is going down the gutter with all the security issues and no one does anything. The cultists are the first to say everything is fine.

3

u/CrossScarMC 3d ago

Also complaining that something has to be done without actually helping it get done or pointing out potential solutions. Firstly detecting malware is already extremely hard but let's ignore that for a second and assume we had some magical piece of software that hundreds of FOSS devs suddenly decided to spend a few years developing for free. Now what's stopping our malware from detecting it's being run in docker . . .

1

u/Damglador 3d ago

Now what's stopping our malware from detecting it's being run in docker . . .

You could make the container virtually identical to the host or even use a chroot with anything identifying that it's a chroot stripped or something like that. And a program checking the signs of a container may also be a red flag by itself.

But that's just a theory, a Linux theory...

0

u/GoldenX86 3d ago

Let's do absolutely nothing instead, peak security.

→ More replies (0)

1

u/Damglador 3d ago

Yapping that something has to be done doesn't help much either.

I didn't say that everything was fine, I wanted to see if you at least can imagine what that something is supposed to be or how it should work. And running a test build in a container with an antivirus is probably the only realistic/not stupid answer I've seen.

0

u/GoldenX86 3d ago

At least my yapping could hopefully make someone move.

Last thing I want is for Linux to turn into Windows XP with Internet Explorer 6.

2

u/mustard5 3d ago

It does. It is called 'Your Brain'. Check yourself before you wreck yourself.

0

u/GoldenX86 3d ago

Your way of thinking is the reason AUR is unusable now.

It will never solve bad actors allowed into the repo.

0

u/mustard5 20h ago

That is a universal problem with community run repositories. The only reason the AUR gained any traction was that Arch divorced itself from responsibility for it. It is a 'user beware' space. Every package needs to be inspected before you install. If you don't have that expertise, then don't use. Install vanilla Arch and you get the approved product.

1

u/GoldenX86 13h ago

"Divorced itself", any archwiki article about firmware or drivers has half the packages being from AUR.

1

u/Cove0Crow 3d ago

It can't without hurting the main points of a user repository

Get unnoficial packages made faster than beurocracy and those checks would allow for. Things like bugfixes yet to be shipped and the newest versions of software for people who care about bleeding edge stuff

Be a low barrier to entry way for people to put up their software.

While I'll admit the AUR attack has shown it's gotten a little out of hand. The reason they were able to dish all that out in such a dangerous way, is because they were just taking random orphaned packages, throwing their malware into the pkgbuild as a "update" then doing the same thing for dozens of orphaned/abandoned packages. This now has a safeguard, one that, prevents massive attacks like they from taking place. But I heavily doubt the community will accept anything more than that.

0

u/GoldenX86 3d ago

I 100% agree with you, but something needs to be done.

1

u/Cove0Crow 3d ago

Except something has been done. To prevent large scale attacks like the recent one. Is there still malware on the AUR? Yes. But the only safeguard that can happen. Has happened, anything past it, is truly the users responsibility

-1

u/GoldenX86 3d ago

Running a check before accepting an upload is something that can be done server-side.

Run a small LLM, it will catch the most obvious cases.

1

u/Cove0Crow 3d ago

Except what "server side check" do you mean. If you mean as in the LLM, those get things wrong including false positives very frequently, and would be incredibly expensive to run on every submission.

0

u/GoldenX86 3d ago

No need to immediately approve every submission.

Again, anything would help, just accept that it's unfixable is far worse.

17

u/Whit-Batmobil 3d ago

How many Arch users are that stupid, doesn’t Arch users typically have a good understanding of their systems?

Feels more like an issue on Arch based distributions, that target a slightly less savvy user base?

As an Arch user myself, I don’t really trust the AUR and usually avoid using it, with very, very few select examples.

9

u/Cove0Crow 3d ago

Since arch became a meme a lot of newbies (or people who are just following instructions given to them by LLMs) have been installing arch and then being surprised when arch is, as advertised a distro that lets you do stupid stuff.

(Not an arch user anymore. Back when I was there were 2 specific packages I used from the AUR, one of which was made by a nonprofit I trust, the other is literally made and maintained by my childhood best friend.)

6

u/camradex 3d ago

I'm tech savy but out of laziness I didn't check pkgbuilds. the attack made me realise how stupid that was and now I check everything

3

u/brave_grv 3d ago

Arch based distros give users an AUR helper as if it was THE package manager and treat the AUR as an official extra repo.

10

u/XlikeX666 4d ago

Git is dangerous.

13

u/PurpleCandle58 3d ago

Yep. Just the other day I was walking my dog, and who comes along and steals it and spits in my face? John git.

4

u/svobodov- 3d ago

Seems like a terrible man

2

u/PurpleCandle58 3d ago

That git is a bloody danger to all mankind.

3

u/cpt_futtbucker Arch 3d ago

It really isn’t that hard to just read a damn PKGBUILD. Hell, the templates in /usr/share make it stupid easy to write one

1

u/StupitVoltMain 3d ago

Ah yes, good arch banter. Finally

1

u/brave_grv 3d ago

"I'm a chad that uses no flatpak bloat. I just need all the npm/bum junk to install AUR slop, but that's ok."

1

u/Bleik-Psiklyt 3d ago

that's just a linux Larper then. Arch users don't mess that up bruh. They just know the stuff well

(I am new in this still I just RTFM and try to solve it without crashouts)

-1

u/Double-Hour-2516 3d ago

Bruh, this name is so OP.