Live data from Hacker News

AURpocalypse now: a look at the recent AUR attacks

lwn.net

101–104 of 104 posts

Re: AURpocalypse now: a look at the recent AUR attacks

#101

Earlier quoted context omitted.

> orphaned packages don’t need to be adoptable - doesn’t have to be a flat global namespace Those things sound worse for us who actually use the AUR the way it's meant to be used, being able to "orphan" packages for new maintainers to pick up bring us long-term stability. And since we review random 3rd party software we install from the internet, who does the actual edits doesn't really matter, as long as it's the ri…

> Those things sound worse for us who actually use the AUR the way it's meant to be used, being able to "orphan" packages for new maintainers to pick up bring us long-term stability. And since we review random 3rd party software we install from the internet, who does the actual edits doesn't really matter, as long as it's the right, simple little changes that updates usually are. This is the problem - the AUR has out…

> the AUR has outgrown this mindset and this resistance to recognize this fact is precisely why this problem will keep coming up.

It has outgrown the mindset that AUR is for people who use and follow the advice of Arch Linux? Or what do you mean? What I'm describing is a workflow you can apply today, apply it equally to all packages, and it stops 99% of the hacking attempts and the remaining 1% wouldn't matter if it's via AUR, NPM or Cargo, same issues remain.

> It’s a cultural problem and your mindset is precisely why this will keep happening

I agree that "Anyone can automatically take over 100s/1000s of packages as a maintainer" is a problem, I don't agree that it's a deeper problem than that. Limit each user to be able to take over one package per month, and suddenly we get all the same benefits we have already, + we fix the current issue.

No need to trash the entire AUR when there is one specific feature broken, just fix that feature, then continue your pragmatic life as before.

> As an Arch user I’m honestly embarrassed and I’m going to be looking at distros that aren’t user hostile like this.

To be fair, if I ended up misunderstand something so deeply that I didn't realize how to actually use it, I'd be embarrassed myself as well, strong of you to at least state so publicly. I'm happy you at least figured out that Arch Linux isn't for you, and you start trying to find a distribution that fits you better, rather than going through a tough period of time trying to change something into a direction it isn't even aiming for.

Re: AURpocalypse now: a look at the recent AUR attacks

#102

Earlier quoted context omitted.

> that Arch security is so bad regarding how they maintain the AUR I still don't understand what people expect Arch to do here? It's a user-contributed repository open for anyone, Arch maintains their own official repositories that are separate from AUR, what would need to change in the maintenance of the AUR for you to consider it to be "properly run" or whatever, and it doesn't stop serving its core purpose anymore…

> The AUR is maintained by Arch's Package Maintainers So, firstly it is their responsibility. The consequences are a direct result of their policies. Example of changes: * orphaned packages don’t need to be adoptable. * doesn’t have to be a flat global namespace * they could have offered the cooldown capability a long time. This isn’t an area they focus on until they’re absolutely forced into it through sheer embarra…

Installing anything from the AUR, it has always been the user's responsibility to check whatever they are installing. Has always been this way, and they have always been abundantly clear about this. It is also the reason why archlinux does not provide an official installer like yaourt or yay, they could've even built support for the AUR into pacman.

The AUR is just as safe as installing through a random shell script from github - that is to say: not safe at all.

Re: AURpocalypse now: a look at the recent AUR attacks

#103
post #100
post #99

Earlier quoted context omitted.

Windows where you just download .exe and .msi files from random websites. Not a Linux distro, but the closest security model I can think of.

You think that users having to find and download software from the Internet at large is both similar to the AUR model and has preferable handling of these issues? Can you elaborate?

To me, installing software from the AUR sounds a lot like downloading Windows software from .info sites and torrents. It's mostly fine, but it's not exactly a surprise when things go wrong.
Post reply on HN