Live data from Hacker News

AUR packages compromised with Infostealer and Rootkit

discourse.ifin.network

231–234 of 234 posts

Re: AUR packages compromised with Infostealer and Rootkit

#231
I'm running OpenSnitch on my desktop machine to get notified about any attempted outgoing network connections by processes that I have not explicitly allowed before. I wonder if this would have at least prevented any data exfiltration if I would have installed one of the infected packages?

I'm thinking more and more that things like sandboxing and compartmentalization are becoming increasingly important on everyday desktop machines. The design of every process having at least read access to almost everything on a machine by default is not appropriate anymore.

Re: AUR packages compromised with Infostealer and Rootkit

#232
post #62
post #36

Earlier quoted context omitted.

The canonical answer to any concerns with the AUR is always “just read the PKGBUILDs bro”

For every single update, for all your AUR packages, all the time. You know that thing where if you make a security review feature obnoxious, after some time people will just accept everything without even looking? Yeah...

Most people should just be using debian stable really.

Re: AUR packages compromised with Infostealer and Rootkit

#234

Earlier quoted context omitted.

AUR is choice, rolling release is the reason

No, it's not. If Debian had a community-maintained repo of additional packages, the same thing could happen there. The fundamental problem is having something that has very loose oversight and next to no controls. That may have worked in the past, but in the day and age of constant supply chain attacks, it's a major liability.

Community-maintained repo is again a choice/option, how does that changes from LTS to Rolling release ?
Post reply on HN