Live data from Hacker News

Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

lists.archlinux.org

111–120 of 142 posts

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#111
post #41

Earlier quoted context omitted.

Plenty of package managers (such as `yay`) install from AUR by default.

On one hand, the distro developers can’t really prevent people from, say, hitting their computers with a sledgehammer or something. So to some extent, the users have to be trusted. But, maybe it would be best not to have “yay” available. Using something like AUR without reading the package build files is… pretty bad, right? And it is bad for the community, because if there is a convention of doing that sort of thing,…

> But, maybe it would be best not to have “yay” available. Using something like AUR without reading the package build files is… pretty bad, right? And it is bad for the community, because if there is a convention of doing that sort of thing, it makes the AUR a good target for attacking.

I don't remember how yay works but paru (another AUR package manager) displays the pkgbuild file before it will install.

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#113
post #112

It seems odd that this is just on the AUR mailing list, and it the homepage, the announce list, or the security list.

Why would it be? AUR is user generated content by definition, you're expected to read and understand every package before using it, which is repeated in documentation ad nauseam. They're very, very explicit about this and that you're on your own when using AUR.

All decent AUR helpers (which arch developers advise against using anyway) force you to read through the packaging script and confirm that you understand it and are fine with what's about to be executed.

It's no more of an issue than someone posting a malware script into e.g. the wiki. Much less obscure than malware in npm or anything like that.

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#114

Earlier quoted context omitted.

yay is a package manager that has been made for AUR. yay is not the official package manager for Arch Linux, pacman is, and it does not support AUR. yay is not installed on Arch Linux by default, its official package manager, pacman, is. AUR is for unofficial 3rd party packages, i.e. "use at your own risk". It has always been the case.

Yes, it is "use at your own risk" but most arch users just install from it without giving it a second thought, because availability of packages in the AUR is the one thing Arch is good at.

It's also good at being fairly simple and transparent, and having the only sane package format in existence (along with Alpine's apkbuild which is basically the same thing), but okay.

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#115

There's always been this security theater of people recommending arch because they "don't trust the companies" or Canonical or what have you but frankly I'm surprised this hasn't happened sooner. Well or maybe it has and we don't know. Running random binaries on your computer uploaded by some anonymous dude has to be the equivalent of buying heart medicine on craigslist. And because Arch is so barebones to begin with…

I agree, it's much better in Ubuntu land where you simply won't have the software at all, will shrug your shoulders and go on with your life.

AUR helpers make reviewing changes to AUR packages a trivial matter that takes about 2 minutes of my life per month. In exchange I get easy access to software that isn't packaged for Ubuntu and probably never will be, because building debs and going through the process of upstreaming them is roughly comparable to getting a PhD (if anyone is even interested in your debs, which they probably won't be).

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#116
post #112

It seems odd that this is just on the AUR mailing list, and it the homepage, the announce list, or the security list.

Why would it be? AUR is user generated content by definition, you're expected to read and understand every package before using it, which is repeated in documentation ad nauseam. They're very, very explicit about this and that you're on your own when using AUR. All decent AUR helpers (which arch developers advise against using anyway) force you to read through the packaging script and confirm that you understand it a…

This feels like a non-sequitur.

Yes, the AUR is user-provided content. Yes, system administrators are responsible for being aware of what they’re installing. You can find many comments from me on this page discussing that.

An attacker being detected using an official service hosted by Archlinux for user-managed packages to push malware is still noteworthy.

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#117
post #95

Earlier quoted context omitted.

How exactly is Arch barebones? It basically ships with everything I need, more than most distros (Zed and Discord are good examples). I don't even need to use the AUR.

Just by taking a glance at the most popular packages ( https://aur.archlinux.org/packages ) Pretty much every browser that isn't Firefox including Chrome, VS Code, most proprietary software like Slack, Zoom, Spotify, many vpn clients and password managers, a lot of them seemingly not published by the companies in question. All of those ancillary password, vpn or security related products who aren't going to be in the…

Some of those packages (like Brave) are maintained by original developers, it depends on the package.

Most aren't, but it's trivial to review changes to packages (all good AUR helpers show the diff on upgrades, an 99% of time the changes are hash and version, nothing else).

So you only need to check the package once, which the documentation reminds you to do about fifty times. Otherwise — play stupid games, win stupid prizes.

If the package has any popularity at all, you will get lots of paranoid users who will eat you alive and report to Arch maintainers right away if you do anything suspicious, try to link a binary from some weird website instead of the upstream URL, or even just omit the GPG signature verification key when it's available.

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#118
post #49

Earlier quoted context omitted.

The only thing I've seen Arch exploding in popularity has been memes. It's a fun distro for hobbyists, but too inconvenient as a daily driver.

Can you elaborate why you think this? Personally I've been running Arch on my work machine for a few years now with very few issues. I'm not even very consistent with updates, and probably run them about once every 3 weeks on average. I have only had to manually intervene on a handful of occasions. I like it a lot because everything is always up-to-date. I don't face any issues with unsupported versions for tools lik…

I'm hesitant to comment further seeing I've attracted the ire of some people with my comment, but anyway. I too used Arch out of curiosity about like ten years ago, during the first "Arch, BTW" memes, and found it too unstable, but that's expected from a rolling release: update too soon or too late, and something could break. I didn't mind, as it was a hobby.

Eventually, I got more busy and had less time to tinker, so I migrated to Ubuntu LTS, which has some small warts, but has needed practically null babysitting compared to Arch. I was surprised when the Arch memes resurfaced this year, but that's the only growth I've seen. None of my Linux-savvy peers use Arch, BTW.

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#119
post #103

Earlier quoted context omitted.

As @lillylizard pointed out, it turns out that these are new packages, not comprised existing packages like I first thought. Still, the nature of the hack is a Remote Execution, as you pointed out elsewhere, meaning the hacker could pull my router password from the password manager, or grab my SSH keys and log into whatever machine is listed in the known_hosts, or just mess with my Ebay account and the credit card sa…

Sure, but only if you’d installed the affected AUR packages. Even if they were old packages, probably your SteamOS didn’t install them from the AUR.

Whether or not SteamOS installed them is irrelevant. All the hacker would need is to compromise a machine that had some sort of remote access to other devices (ssh in this case, with some sort of keylogger to decrypt the private key).

Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

#120
post #116

Earlier quoted context omitted.

Why would it be? AUR is user generated content by definition, you're expected to read and understand every package before using it, which is repeated in documentation ad nauseam. They're very, very explicit about this and that you're on your own when using AUR. All decent AUR helpers (which arch developers advise against using anyway) force you to read through the packaging script and confirm that you understand it a…

This feels like a non-sequitur. Yes, the AUR is user-provided content. Yes, system administrators are responsible for being aware of what they’re installing. You can find many comments from me on this page discussing that. An attacker being detected using an official service hosted by Archlinux for user-managed packages to push malware is still noteworthy.

I guess we have very different takes on this; I wouldn't expect Slack or WhatsApp to publish security advisories if one of their users used them to spread malware among a tiny cohort of other users, which is about the right level of responsibility Arch places on itself (and it's very clear about this) w.r.t AUR.
Post reply on HN