Live data from Hacker News

Arch Linux AUR Repository Found to Contain Malware

sensorstechforum.com

21–30 of 137 posts

Re: Arch Linux AUR Repository Found to Contain Malware

#21
The article mentions 3 infected packages. But it only lists one: acroread.

Then the comment section mentions the other one is libvlc.

But the mailing list says this is something different: https://lists.archlinux.org/pipermail/aur-general/2018-July/...

So then there's still two missing.

Here's what I've found that he maintained:

1) balz (https://archive.fo/TjIQI)

2) minergate (https://archive.fo/TjIQI)

3) acroread - as mentioned (https://my.mixtape.moe/kvfpmk.png)

So those "balz" and "minergate" could be the missing two.

Edit: seems like archive.fo is temporarily down, so it will just be my word for it right now. Sorry.

Re: Arch Linux AUR Repository Found to Contain Malware

#23

The article mentions 3 infected packages. But it only lists one: acroread. Then the comment section mentions the other one is libvlc. But the mailing list says this is something different: https://lists.archlinux.org/pipermail/aur-general/2018-July/... So then there's still two missing. Here's what I've found that he maintained: 1) balz ( https://archive.fo/TjIQI ) 2) minergate ( https://archive.fo/TjIQI ) 3) acrorea…

Someone was questioning if `libvlc` could be considered dangerous. However the package download our packaged `vlc` packages and just repackages the `/usr/lib/libvlc*` files into a new package.

Re: Arch Linux AUR Repository Found to Contain Malware

#24
post #8
post #3

Earlier quoted context omitted.

The thing is not that it's a new deficiency or something, it's just that Arch user conveniently ignore this when praising their distribution over e.g. Debian.

AUR repository isn't supported by the core tools and packages. To use it one has to install external scripts. So it's by no means part of the system.

All it takes to build air packages is makepkg from the core pacman package. With gut you can grab aur packages from the terminal, and hit is also core. Every Arch install must have pacman and hit is in base-devel, a package group in core all AUR pkgbuilds are designed to assume is installed.

Re: Arch Linux AUR Repository Found to Contain Malware

#25

Earlier quoted context omitted.

Who would want to use a rolling release distribution for a (production) server? Sounds like a pretty terrible choice, to be quite honest.

All of the Arch Linux infrastructure is run on Arch. Works pretty well.

There is an expectation that projects dogfood their own software, but I really can't think of a rational reason for a production server not affiliated with the Arch project to be running Arch.

Rolling release is great for technically competent users to install on their workstations, but why would you ever want a rolling release on a production server?

Re: Arch Linux AUR Repository Found to Contain Malware

#27

Earlier quoted context omitted.

Fortunately admins are not unreasonable and don't base their decisions on praises but on actual merits, so most servers run Debian rather than Arch (which is an interesting distro for other usage cases).

Who would want to use a rolling release distribution for a (production) server? Sounds like a pretty terrible choice, to be quite honest.

Nobody that values their job or sleeping well at night. It's basically one level of nuts above and beyond running Debian Sid on all your production servers.

Re: Arch Linux AUR Repository Found to Contain Malware

#28
post #5

Not a surprise.

Yes, but this may be a good reminder for fellow Arch users who have grown complacent reviewing things they install from AUR. I've gotten to the point where I do not install any AUR helpers on my systems, and manually download PKGBUILDs and install with makepkg. These extra steps force me to 1) review the PKGBUILD + *.install files, and 2) make me reconsider whether or not I want to go through the effort for a package…

I've seen the advice of not installing AUR helpers multiple times before. I guess it works for many, but I feel it takes more discipline to review the files when not using AUR helpers since you can just download them and makepkg them immediately, while all AUR helpers I've seen explicitly ask you if you'd like to first review the files in an editor with a default answer of [Y]es.

Re: Arch Linux AUR Repository Found to Contain Malware

#29
post #17
post #8

Earlier quoted context omitted.

AUR repository isn't supported by the core tools and packages. To use it one has to install external scripts. So it's by no means part of the system.

Which, as I said, very conveniently is glossed over by Arch users.

That's a problem with Arch users, not with Arch. It's unfortunately common that fanboys undermine the reputation of reasonable software.
Post reply on HN