Arch Linux AUR Repository Found to Contain Malware
sensorstechforum.com
Arch Linux AUR Repository Found to Contain Malware
1–10 of 137 posts
Re: Arch Linux AUR Repository Found to Contain Malware
#2There's a whole lot of trust that has to go on when installing a package from the AUR - and yes, this is a fundamental problem with the security model of Arch Linux, but that's been known for a very long time.
Honestly, I'd be surprised if this hasn't happened before with orphaned packages.
Re: Arch Linux AUR Repository Found to Contain Malware
#3The Arch User Repository hosts whatever people want to upload to it, with basically no proactive vetting whatsoever. In addition, the installation scripts run arbitrary code, a portion of which must run with root privileges. When a package gets orphaned, that means that anybody in the community can take over maintainership of the package. There's a whole lot of trust that has to go on when installing a package from t…
Re: Arch Linux AUR Repository Found to Contain Malware
#4"This is yet another incident that showcases that Linux users should not explicitly trust user-controlled repositories."
LOL. Why should this only apply to Linux users? We should all be wary of downloading random things from websites.
AUR has always been labeled "user submitted", but I guess it's easy to forget that some "users" are really out to cause harm.
Re: Arch Linux AUR Repository Found to Contain Malware
#5Re: Arch Linux AUR Repository Found to Contain Malware
#6The Arch User Repository hosts whatever people want to upload to it, with basically no proactive vetting whatsoever. In addition, the installation scripts run arbitrary code, a portion of which must run with root privileges. When a package gets orphaned, that means that anybody in the community can take over maintainership of the package. There's a whole lot of trust that has to go on when installing a package from t…
The thing is not that it's a new deficiency or something, it's just that Arch user conveniently ignore this when praising their distribution over e.g. Debian.
Re: Arch Linux AUR Repository Found to Contain Malware
#7Re: Arch Linux AUR Repository Found to Contain Malware
#8The Arch User Repository hosts whatever people want to upload to it, with basically no proactive vetting whatsoever. In addition, the installation scripts run arbitrary code, a portion of which must run with root privileges. When a package gets orphaned, that means that anybody in the community can take over maintainership of the package. There's a whole lot of trust that has to go on when installing a package from t…
The thing is not that it's a new deficiency or something, it's just that Arch user conveniently ignore this when praising their distribution over e.g. Debian.
Re: Arch Linux AUR Repository Found to Contain Malware
#9Earlier quoted context omitted.
The thing is not that it's a new deficiency or something, it's just that Arch user conveniently ignore this when praising their distribution over e.g. Debian.
Fortunately admins are not unreasonable and don't base their decisions on praises but on actual merits, so most servers run Debian rather than Arch (which is an interesting distro for other usage cases).
Re: Arch Linux AUR Repository Found to Contain Malware
#10I mean, is this new information? I always look at the upvotes on the package to see if it has been tested.