Earlier quoted context omitted.
This feels like a non-sequitur. Yes, the AUR is user-provided content. Yes, system administrators are responsible for being aware of what they’re installing. You can find many comments from me on this page discussing that. An attacker being detected using an official service hosted by Archlinux for user-managed packages to push malware is still noteworthy.
I guess we have very different takes on this; I wouldn't expect Slack or WhatsApp to publish security advisories if one of their users used them to spread malware among a tiny cohort of other users, which is about the right level of responsibility Arch places on itself (and it's very clear about this) w.r.t AUR.
Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
121–130 of 142 posts
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#122Earlier quoted context omitted.
It's ArchLinux. The user is expected to do their own due diligence.
And these packages are from AUR, they are not officially supported. AUR means Arch User Repository. You cannot even use Arch Linux's official package manager to install AUR packages either, you need an AUR helper ("makepkg" is sufficient though but it has limitations). These AUR helpers are not even official packages either. Not even yay: https://archlinux.org/packages/?sort=&q=yay .
My desktop OS is much less of a concern now, so I mostly use macOS. It provides a decent shell and otherwise stays out of my way. I use Windows for gaming.
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#123When installing softwares on arch Linux, first searching for official packages provided by Arch Linux maintainers, then official installation methods approved by authors of the software, or AURs which do the installation in the exact way as the authors of the software describe.
A search on the default installation method of Firefox and librewolf package on arch Linux is listed below.
If AUR is required to install a package, note that AURs are not trusted by default because not all AURs are not maintained by trusted users. Always check the source file and the installation method documented in PKGBUILD. Don't do the installation until EVERY line in the PKGBUILD is reasonable.
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#124Earlier quoted context omitted.
Sure, but only if you’d installed the affected AUR packages. Even if they were old packages, probably your SteamOS didn’t install them from the AUR.
Whether or not SteamOS installed them is irrelevant. All the hacker would need is to compromise a machine that had some sort of remote access to other devices (ssh in this case, with some sort of keylogger to decrypt the private key).
- librewolf-fix-bin
- firefox-patch-bin
- zen-browser-patched-bin
The packages were only available for download for 3 days, and the only way you could have installed them is if you explicitly typed one of the package names into your terminal within those 3 days.
Did you do that? If no, then you are not compromised.
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#125Earlier quoted context omitted.
Can you elaborate why you think this? Personally I've been running Arch on my work machine for a few years now with very few issues. I'm not even very consistent with updates, and probably run them about once every 3 weeks on average. I have only had to manually intervene on a handful of occasions. I like it a lot because everything is always up-to-date. I don't face any issues with unsupported versions for tools lik…
I'm hesitant to comment further seeing I've attracted the ire of some people with my comment, but anyway. I too used Arch out of curiosity about like ten years ago, during the first "Arch, BTW" memes, and found it too unstable, but that's expected from a rolling release: update too soon or too late, and something could break. I didn't mind, as it was a hobby. Eventually, I got more busy and had less time to tinker, s…
I've had way more problems with Ubuntu trying to be convenient and bringing in lots of Windows-style automation that breaks more often than it works (and when that happens, you're really on your own since you have no idea how it's put together — just like in Windows).
Or even just bugs that were solved upstream ages ago (and have been available in every rolling-release distribution, including Debian testing/sid).
The current Arch installer suggests btrfs with snapper, so you get automatic snapshots pretty much out of the box (need to check one flag in installer), and can easily rollback if something breaks. Not something I needed, but it's there.
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#126Earlier quoted context omitted.
Just by taking a glance at the most popular packages ( https://aur.archlinux.org/packages ) Pretty much every browser that isn't Firefox including Chrome, VS Code, most proprietary software like Slack, Zoom, Spotify, many vpn clients and password managers, a lot of them seemingly not published by the companies in question. All of those ancillary password, vpn or security related products who aren't going to be in the…
And what distro does package those? That's what Flatpak is for. If you must install crappy proprietary software, at least get an official package from the developer.
nix, which has its own share of problems.
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#127Earlier quoted context omitted.
On one hand, the distro developers can’t really prevent people from, say, hitting their computers with a sledgehammer or something. So to some extent, the users have to be trusted. But, maybe it would be best not to have “yay” available. Using something like AUR without reading the package build files is… pretty bad, right? And it is bad for the community, because if there is a convention of doing that sort of thing,…
Yay is a 3rd party package manager. The 1st party package manager does not interact with the AUR. Yay itself is in the AUR. You have to go out of your way to install it. The Archlinux docs on AUR helpers lead with a red warning: https://wiki.archlinux.org/title/AUR_helpers
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#128Earlier quoted context omitted.
Did you install one of those packages? If yes, nuke from orbit. More interesting questions are: - Who was the uploader? A packager? For how long? - Do they maintain other packages? - What steps can be taken to ensure that a similar problem doesn't happen in future?
Per the Wayback Machine the username used was danikpapas. As far as Google and duckduckgo know these are the only packages theat username ever uploaded. Considering the purpose was crime it's likely that that username was "stolen" and the person using it on other sites wasn't the same as the one doing this... The AUR is arch's repository of untrusted user maintained read-the-source-before-installing packages. There's…
I mean... ... if this was a malicious actor who is to say they don't have 15 aliases on 5 linux distros
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#129Earlier quoted context omitted.
But their differentiation is that to improve performance they compile all the packages with newer instruction sets as the target as well as enabling more optimizations like LTO. And some are even optimized with PGO.
I find it odd to call a specific Linux distribution blazingly fast. Gentoo with make.conf (/etc/portage/make.conf[1]) having "CFLAGS="-O3 -march=native -flto"" means that Gentoo, a Linux distribution, is performant? [1] It is not a good idea to build everything with LTO or PGO enabled because not all packages support LTO / PGO cleanly. Do it on the basis of per-package.
For me it feels blazingly fast, even on obsolete KabyLake Core-I5/7(t) forcibly clocked down to about 800Mhz most of the times :)
It fucking flies without much effort. On modern systems even more so. While being rock solid. Without any crashes. Even under Plasma. When I'm reading about bugfixes regarding crashes under Plasma I just shrug and think "Waddya talkin about?". That may be hardware dependent, though, because they are old Lenovo Thinkcentres(1Litre SFF M910q tiny) with excellent firmware.
Using btrfs, profile-sync-demon, zram(Yes. Even with 32GB Ram!). Suspend/Resume working every single time. No glitches, hick-ups, ever. So far. Since 10th of June, 2024.
Edit: Almost always some music out of yt doodling in some bg-tab, in oh-so-slow FF, without any clicks, stuttering, or other breaks.
No need for yt-dlp, mpv at all. Except for dl/saving stuff, sometimes. While FF is rarely under 100 tabs.
Re: Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
#130As Arch seemingly explodes in popularity I’m afraid we’ll start seeing more of this.
The only thing I've seen Arch exploding in popularity has been memes. It's a fun distro for hobbyists, but too inconvenient as a daily driver.
Then had to use something 'officially' supported for a while, then did some Debian derivative live-distro running from USB/in RAM because of HW-problems, and settled for CachyOS when new (old) HW arrived.
I update maybe once a month at the most, more likely every two monts, because I don't give a shit. With the exception of FF, or maybe some nicer Kernel, for eBPF and scheduler-stuff.
That's reviewing changes in a few config files, after having read up about them at Archs & CachyOS sites. Maybe five minutes max, opening a few relevant tabs. (If necessary at all, which often isn't the case.)
Starting Pacman. Downloads instantly, even if several GB. Decompresses and installs stuff. Maybe two to three minutes. Reboot. 20 seconds. Plasma is back.
Clicking FF. Back with all its tabs. Maybe two to three seconds. Maybe uBO blocks a few more secs sometimes, while updating lists.
After intentionally having killed it with -9 in preparation before reboot.
Cleaning Pacman's package-cache and btrfs-snapshots because The only way is Fooorwaaard!
( https://www.youtube.com/watch?v=e_tVzx_PIH8 Daxon ft. Numa - The Only Way (Extended Mix) [COLDHARBOUR RECORDINGS] 7mins, 7secs )
Letting btrfs rebalance in the background.
Opening other stuff, on other virtual desktops, being exactly where and how I left it, thanks to working session-mgmt.
Feels very convenient to me, in opposition to most of the other 'mainstream stuff'.
Maybe the memes have a core of truth to them? For ppl who know what they do?
Cachy, Cachy, Caramba, Yay, Yay!