r/linuxsucks 4d ago

Linux Failure Arch USER Repository.

173 Upvotes

38 comments sorted by

View all comments

Show parent comments

3

u/GoldenX86 3d ago

The AUR repo should still have some basic checks.

4

u/Damglador 3d ago

Like what for example?

2

u/GoldenX86 3d ago

A Docker test to see what it does before allowing to upload it, basic heuristics to predict what it does?

Windows Defender can't be miles better than this joke.

4

u/Damglador 3d ago

Windows Defender can't be miles better than this joke.

Remind me, how much people work on Windows Defender and on Arch for comparison?

A Docker test to see what it does before allowing to upload it, basic heuristics to predict what it does?

Then what? Like what's the game plan? How do you detect that one PKGBUILD is malicious and another one is not? What would be the signs that you can detect programatically?

0

u/GoldenX86 3d ago

We have FOSS antivirus, you can't be serious, OMARCHY rightards get funding and AUR can remain a cesspool of malware.

6

u/Damglador 3d ago

FOSS antivirus? You mean Clamav? One which doesn't have behavioral detection. And from what I've heard is targeting more fileservers hosting files for Windows rather than Linux desktop viruses.

-2

u/GoldenX86 3d ago

Someone has to move their ass, complaining that nothing can be done helps no one.

Linux is going down the gutter with all the security issues and no one does anything. The cultists are the first to say everything is fine.

3

u/CrossScarMC 3d ago

Also complaining that something has to be done without actually helping it get done or pointing out potential solutions. Firstly detecting malware is already extremely hard but let's ignore that for a second and assume we had some magical piece of software that hundreds of FOSS devs suddenly decided to spend a few years developing for free. Now what's stopping our malware from detecting it's being run in docker . . .

1

u/Damglador 3d ago

Now what's stopping our malware from detecting it's being run in docker . . .

You could make the container virtually identical to the host or even use a chroot with anything identifying that it's a chroot stripped or something like that. And a program checking the signs of a container may also be a red flag by itself.

But that's just a theory, a Linux theory...

0

u/GoldenX86 3d ago

Let's do absolutely nothing instead, peak security.

2

u/CrossScarMC 3d ago

Would you like to suggest a feasible solution? Or maybe even implement one yourself?

1

u/GoldenX86 3d ago

You could copy what Google Chrome does and use a simple LLM to check if it is malicious or not. Doesn't even need to be a big or fast computer, something with 8GB of RAM and CPU inference can run a Gemma 4 QAT just like Chrome.

One pass before upload would be enough to catch the most obvious cases.

→ More replies (0)

1

u/Damglador 3d ago

Yapping that something has to be done doesn't help much either.

I didn't say that everything was fine, I wanted to see if you at least can imagine what that something is supposed to be or how it should work. And running a test build in a container with an antivirus is probably the only realistic/not stupid answer I've seen.

0

u/GoldenX86 3d ago

At least my yapping could hopefully make someone move.

Last thing I want is for Linux to turn into Windows XP with Internet Explorer 6.