• Vendetta9076@sh.itjust.works
    link
    fedilink
    arrow-up
    2
    ·
    11 hours ago

    I feel like when this pops up everyone freaks out and yells about how it’s proof the aur sucks and arch is doomed. Do you people randomly install GitHub repos without any due diligence? Do you click on random ads to download bake bean can cursors? There’s malware fuckin everywhere. Just do your due diligence and don’t get screwed. And if you do get malware, have a plan to make it irrelevant. Anyone who doesn’t do these things should in no way be using the AUR.

  • Asonyxi@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    1 day ago

    Man I feel like I dodged a bullet switching to Fedora right before this AUR fuckery started to happen…

    • motruck@lemmy.zip
      link
      fedilink
      arrow-up
      6
      ·
      1 day ago

      You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.

      • bleustenns@lemmy.ml
        link
        fedilink
        arrow-up
        5
        ·
        2 days ago

        Yeah, there’s a ton of people that recommend Cachy when it is really meant for tinkerers IMHO

        • LordKitsuna@lemmy.world
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          23 hours ago

          I’m very tired of the rhetoric that Arch is only meant for tinkerers. If all you do is have plasma steam and a web browser it’s no more or less likely to break than any other distro. You could go your entire life without ever looking at the terminal.

          And while yes this malware is a problem it is specifically in the aur, the arch user repository an unofficial repository not officially supported, just don’t use it. Unless you need a weird piece of software generally related to some type of specific hobby you’re unlikely to ever even want to look at it anyway.

        • peetabix@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 days ago

          I suppose so. I run Cachy now but that’s only after 3 years of switching distros several times and getting more confident with how Linux works.

    • thingsiplay@lemmy.ml
      link
      fedilink
      arrow-up
      27
      arrow-down
      1
      ·
      3 days ago

      Adoption of unmaintained packages to maintain them is not a mistake. The problem is the current implementation, not the idea behind it. It’s like saying the AUR is a mistake, because some people do malicious stuff.

      They should find a better solution, like adoption shouldn’t be granted to everyone without question, especially new accounts who didn’t maintain anything before. Mass adoption shouldn’t be granted automatically (limit rate), in example 1 package adoption per day and if someone wants more, admins or moderators need to approve. And updates of newly adopted packages should wait a day.

      Also the AUR helpers should do a better job. Always ask if a new adopted package should be updated and give a warning the maintainer changed.

      • 𝘋𝘪𝘳𝘬@lemmy.ml
        link
        fedilink
        arrow-up
        8
        ·
        3 days ago

        The problem is the current implementation

        Yes, exactly this! I am not surprised it happens. I’m surprised it didn’t happen before.

        especially new accounts

        Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

        Also the AUR helpers should do a better job.

        Even experienced people will just update as if nothing could happen. Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

        • thingsiplay@lemmy.ml
          link
          fedilink
          arrow-up
          4
          ·
          3 days ago

          Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

          Which does not invalidate my point about new accounts, but yes. Its important for new accounts, so once a sleeper account is banned, its not that easy to just create thousands of new accounts while everyone is focusing on the current active ones. And if, as I suggested, mass adoption per account is not possible, then the attacker has less to attack.

          Edit: They need to make sure that sudden editing many packages in short time, with probably the same or similar lines should be automatically reported. They need some automated checks in place, at the very least. This would be a very suspicious behavior if many accounts are not active, and then suddenly all of them do something.

          Even experienced people will just update as if nothing could happen.

          Then you can’t fault the system, if you are this reckless.

          Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

          This would break all dependencies of this package. The point of adoption is to keep it working and stable. I’m highly against force changing the name, that is not a solution (at least not one I am happy about).

          • 𝘋𝘪𝘳𝘬@lemmy.ml
            link
            fedilink
            arrow-up
            4
            ·
            3 days ago

            [Changing a package’s name] would break all dependencies of this package.

            Yes, that is correct. But that should not be a big deal for packages that are actively maintained. The maintainer can simply change the dependency to the new name after making sure the new package is legit.

            • thingsiplay@lemmy.ml
              link
              fedilink
              arrow-up
              4
              ·
              3 days ago

              OK, that’s a good point. It would prevent auto updating. However any package that is NOT updated, should stay with same name in my opinion. So that everything (with the old secure code) stays intact and working. The name change should be part of the the update process. So it only breaks if you want to update, which would ensure compatibility if you choose not to (as it is safe). Something along the likes like this. I agree with your suggestion now, because that seems to be sensible idea.

  • LiveLM@lemmy.zip
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    2 days ago

    Why tf didn’t they leave it disabled since the last attack?

      • eremophila@lemmy.zip
        link
        fedilink
        arrow-up
        3
        ·
        2 days ago

        I only use official and flatpak, I wouldn’t even use flatpak if official had more.

        Chaotic aur might be worth looking into if aur is what you want. Everything there is theoretically checked.

        • JC1@lemmy.ca
          link
          fedilink
          arrow-up
          1
          ·
          2 days ago

          Are you sure about chaotic? I removed it as I thought it wasn’t really checked as I read in a comment here.

          • eremophila@lemmy.zip
            link
            fedilink
            arrow-up
            1
            ·
            1 day ago

            might be worth looking into

            I’m not sure of anything, I would look into it further were I planning on using it, which I might do in the future, Garuda KDE lite looks like a decent distro.

            From the little I have looked into it, it is all meant to be checked, adding an extra layer of protection, as long as your trust the people behind it (much like official I guess)

    • Eggymatrix@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      2 days ago

      I mean, nobody is saying there is no way to prevent this, and I would hardly say that “twice” can be cathegorized as regularly.

      Also I find this of extremely bad taste as you seem to compare this to school shootings, with literal children deaths. I would say that a few thinkerers getting pwned from their claude tokens is a couple orders of magnitude less serious.

    • BradleyUffner@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 days ago

      Isn’t this similar to the reason a lot of people hate snaps? Or am I misunderstanding something? I’m not an Arch user (btw) so I’m not super familiar with AUR.

    • thingsiplay@lemmy.ml
      link
      fedilink
      arrow-up
      5
      arrow-down
      4
      ·
      3 days ago

      Besides all the other non infected ways to install the software, there is a way to prevent this: Just read the AUR package before install and don’t trust blindly any new maintainer.

      • Faux@lemmy.ml
        link
        fedilink
        arrow-up
        7
        arrow-down
        2
        ·
        3 days ago

        It’s metaphysical approach to security. Enshrined rules that can’t be enforced don’t define user’s behavior.