3 ms·
With regards to sandboxing etc. maybe. With regards to packages? Official repos support signing and usually rely on maintainers with proven track records. AUR w
by Matl 2mo ago
With regards to sandboxing etc. maybe. With regards to packages? Official repos support signing and usually rely on maintainers with proven track records. AUR was a honor system and since some people are total basement losers, you can't rely on that.
- Alive-in-2025 2mo agoWe have locks on our doors for a reason. Any software that allows updates and relies on the honor system of "someone else must have checked this" will get hacked. Every day there's yet another certificate or secret stealing infection that is in some random upstream dependency in your dev tools or shell scripts or whatever.
- Matl 2mo agoYes, my point being this isn't some 'Desktop Linux security' hole. This was a known and intentional model of how the AUR operated for decades. Unfortunately it was bound to get exploited like this and so it did.
- thayne 2mo ago> Any software that allows updates and relies on the honor system of "someone else must have checked this" That is never how the AUR was supposed to work. Updates were intended to be a manual process where the user reviewed changes to the PKGBUILD.
- preg_match 2mo agoYes but realistically trust is necessary, as users can’t audit all source code. The fact the source code is even audited is, in it of itself, a blessing. Google Play and the App Store don’t do that, and those are trust based systems as well. And naturally, malware slips through, as it always will.
- Matl 2mo agoThe AUR is not like Google Play. Arch has https://archlinux.org/packages https://archlinux.org/packages for that. The AUR is like an APK from a Reddit post.