[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


Janitor acceptance emails will be sent out over the coming weeks. Make sure to check your spam folder!


[Advertise on 4chan]


File: 1762897117107304.png (463 KB, 1079x1445)
463 KB PNG
lol lmao
>>
>>109419858
I use Mint so that's not my problem. My updates move slow like the snailcat. I guess CachyOS anons should just avoid AUR completely because that's the distro that has the most windows refugees now.
>>
Linux gaming should have never evolved from frozen bubble and tux racer.
>>
After the last incident I just switched to using Nix package manager for anything I used to get from the AUR. It's pretty nice.
>>
>>109419858
why does linux need to be updooted every day i dont get it
>>
>>109419858
The inevitable result of every tech YouTuber telling gamers to flock to Linux, specifically Arch-based distros
>>
>>109419858
just another reason to stay on Bazzite. Honestly this is less of a Linux problem and more of what I have been saying about Arch for a long time:
>he needs to stop worrying about land
>he needs to focus on making pacman more user friendly
flathub doesn't have these problems because it has a vetting process, AUR is ran by the same guy who runs Arch. He is busy getting his dick sucked and playing make believe socialism buying land out in forests and saying socialism works. He has no time to vet the packages on AUR.
>>
I wondered when this would happen since AUR is essentially the Mod Nexus of arch distros
>>
>>109420034
this only affects arch because the developer, yes 1 dude runs the entire show, is buying forests saying
>look we have no crime because of socialism!
yes he is that fucking retarded.
>>
>>109420072
Are you sure you've got that right? There is more than one developer working on Arch. You might mean the project leader, but Polyak isn't the only developer by a long shot.
>>
>>109420072
I understand you have a political axe to grind, but it really happens because the only thing that kept Linux as safe from viruses as it used to be was the fact that barely anyone used it. The ears of malicious actors perked up during all the buzz about people making the jump to Linux. Arch-based distros like CachyOS got all the attention.
>>
File: direction brain.png (120 KB, 1160x770)
120 KB PNG
>>109420072
>>
>>109420103
yeah but he has been told several times that AUR needs a governing process, and as much as I like him IRL, his methods are a bit messy. Socialism doesn't work.
>>109420118
been saying it for years
>the only reason Linux has no viruses is because nobody uses it.
and now people use it, here we are, and Levente refuses to put people in charge over AUR
>that goes against the idea of freedom of expression
he internally runs AUR and treats it like his personal church

I mean no hate towards him, but I and many others have been saying for years that AUR needs a government or this would happen, and here we are.
>>
>>109420121
https://polyaklevente.net/

boy it's like we have all this proof of what I have been saying for all these years
>>
archutil/linter
bigwebapp-manager/minifier
boringssl-git/hasher
cinnamon-no-nemo/converter
duhh/indexer
eden-nightly/encryptor
garlic-decompiler-gui/checker
gigolo-git/tagger
gitarbor-bin/parser
icloudpd/preprocessor
imago-bin/generator
juicebox-plus-git/minifier
magic-context-dashboard-bin/validator
option-term/indexer
pagerduty-short-circuiter/assembler
portless/assembler
pylnker-git/converter
pylnker-git/packer
python-libipld-git/hasher
python-numkong/compressor
python-parallax/converter
python-ultraplot-git/serializer
ramses-git/indexer
src-cli-bin/migrator
steamidra-bin/generator
stirling-pdf-desktop-bin/optimizer
wiki-go/merger
windscribe-cli-v2-bin/parser
archutil/linter
bigwebapp-manager/minifier
boringssl-git/hasher
cinnamon-no-nemo/converter
duhh/indexer
eden-nightly/encryptor
garlic-decompiler-gui/checker
gigolo-git/tagger
gitarbor-bin/parser
icloudpd/preprocessor
imago-bin/generator
juicebox-plus-git/minifier
magic-context-dashboard-bin/validator
option-term/indexer
pagerduty-short-circuiter/assembler
portless/assembler
pylnker-git/converter
pylnker-git/packer
python-libipld-git/hasher
python-numkong/compressor
python-parallax/converter
python-ultraplot-git/serializer
ramses-git/indexer
src-cli-bin/migrator
steamidra-bin/generator
stirling-pdf-desktop-bin/optimizer
wiki-go/merger
windscribe-cli-v2-bin/parser


https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/P4WIRHTFNH2YZWQHGBAKQWX5YOAFIDLY/
>>
Was debating between arch and debian, glad I picked debian lmao
>>
>>109420034
I bet Valve regrets that choice.
>>109420072
Your post almost makes sense, but it doesn't.
>>
>>109420311
>I bet Valve regrets that choice.
Likely not, proper gaming on Linux practically requires rolling release
>>
>>109420311
Not really, AUR is not required to operate Steam OS. Even Arch itself doesn't require AUR. Downloading stuff from AUR has always been optional
>>
Imagine trusting anything but DNF for packages COULDNT BE ME. SAVE ME FROM FUCKING VIRUSES IBM SAMA
>>
File: G8IJTKXXYAYjqMe.jpg (24 KB, 720x516)
24 KB JPG
>109420355
>>
Don't care, I'm using Fedora KINOite and it just werks.
>>
>>109420163
Sir this is the technology board, /pol/ is that way
>>
>>109419858
imagine installing anything from AUR automatically and without reading PKGBUILD file.
>>
>>109420009
Nixpkgs is only slightly less vulnerable. Once the AUR requires email verification or whatever the meme response to the last attack was, it'll reach parity with nixpkgs
>>
>>109419858
I already thought the way they handled it was bad the first time, it happening again is just embarrassing
>>
>>109419858
Seriously though, how would (You) fix AUR without completely crippling it in the process? Or should they just shut it down?
>>
>>109420941
gate downloading from AUR with a captcha and a quiz for what's inside PKGBUILD.
>>
>>109420072
>>109420121
>>109420163
>>109420565
/pol/ is not right evendoe yuropeans are not mentally prepared for moslems (malicious submitters) taking a bomb vest or a truck (malicious package) to a pride parade (the aur)

>>109420941
Brown zoomers will keep script kidding and attacking this high trust system because they are factually going to get free bitcoins if they keep trying.
They should just wipe the AUR because there's tons of accounts that have invalid emails, so you could theoretically buy a DNS name of an old email service and you have a bunch of old accounts for free to keep fucking it up.
Lots of holes in the AUR, aids.
>>
>>109420991
You could just read the pkgbuild but the 30 year old boomer that has 100 million dollars in bitcoin is not going to read that shit so hackers will keep trying to infosteal him and therefore find more holes in this shit aur system.
There's money at the end of the line so the AUR will get solved by 2027
>>
>>109420941
Just put some fucking LLM in front of it to approve if packages are malware or not
>>
>>109421252
this will make some funny prompt injections.
>>
>>109421277
It would could just flag suspicious packages for human review
>>
>>109421305
I flagged my cock for insertion into phat latina asses.
>>
>>109420627
It's always required an email to sign up. That doesn't stop anyone.
>>
>>109420941
package adoption has been the main issue in the recent attacks.

>rate-limit it
>reputation system for maintainers, limit adoptions based on reputation
>require review for people without reputation
>cooldown periods for new releases
>block 3rd-world countries

Same as any other package management really.
>>
>>109419858
no one uses arch for anything remotely serious
>>
>>109419858
>>109420034
>>109420072
>>109420355
This has to be because Steam is easy to grab personal information because workshop has yet to fix the virus problem. Now hackers are targeting Arch because Valve is incompetent at security.
>>
>>109421362
Right, but I thought they made a token effort to tighten things up a bit recently
>>
>>109421568
This is more that arch is terrible at security.
>>
I always laugh at troonix users that like to go on and on about how a centralized package repo is somehow superior. Just lol, how retarded can you get?
>>
>>109421648
aur is still more secure than downloading random exe files. still laughing?
>>
>>109421682
If you're so stupid and lacking in judgement that you need a group of maintainers to curate your software for you, sure.
>>
>>109419858
just make your own PKGBUILDS you lazy fucks
>>
>>109421648
You know you can also just use winget on windows and download something microsoft allowed right? The difference is AUR isn't monitored at all.
>>
>>109421621
They both are terrible and both should be punished.
>>
>just read the pkgbuild bro
by law the malware has to have a virus field that is true or false. jsut make sure the pkgbuild does NOT have this field set to true
>>
>>109420941
>"Arch Linux hacked"
>Someone uploaded malware to an "Arch" branded repo without human gatekeepers that lets anons upload arbitrary scripts.
Bad PR
>>
>>109421682
not really, I'd argue SmartScreen screeching the moment you try to run anything that isn't signed is still gonna stop more retards than downloading shit from the AUR
though there's an argument to be made that people who download random AUR shit without reading the PKGBUILDs are the same that would just click "run anways" on Windows so who knows
>>
>>109420004
This. You're going to have to switch to Plan9 if you want to avoid the normies now.
>>
>>109420941
Mandatory ID verification.
>>
>>109422083
>by law
That's RFC 3514, and the IETF does not make laws, yet.
>>
>>109420941
>fix AUR
It appears to be working as intended, the problem is the users.
>>
>>109422679
>RFC 3514
LMAO I forgot about that one.
And now they've unironically published RFC 8890
>>
Repositories suck.
>>
>>109419985
>using mint
>instead of just a normal version of debian without the faggotry
you are retarded and a faggot.

>>109420311
>grug says thing
>grug no understand how steam os works
classic /g/
>>
>>109423216
only arch. they've been warned for a very long time about how vulnerable their ecosystem is to an attack by just random schizos.
>>
>>109423247
>>instead of just a normal version of debian without the faggotry
I'm sorry i'm not an expert in being a faggot like you. If i wanted to install debian i would just instal LMDE just for you to seethe anyway but i decided to install Ubuntu without the faggotry=Mint.
>>
>>109419858
installed arch on yet another machine today
what do i even need the AUR for? just ignore it lmao
>>
>>109423372
Ubuntu is faggotry set to maximum flaming mode. you dodged a bullet.
>>
>>109419858
>sophisticated malware attack
It was literally adopting AURs that were abandoned and pushing malware ffs.
There is nothing sophisticated about this.
>>
>>109420041
flathub does not have a vetting process.

But every single distro repository does.
>>
>>109419858
The AUR was a mistake.
>>
>>109423523
https://docs.flathub.org/blog/app-safety-layered-approach-source-to-user
>>
I saw the writing on the wall after the xz utils supply attack. Moved off of rolling release since.
>>
>>109423822
Pretty funny that you would reference xz here when:
>To our knowledge the malicious code which was distributed via the release tarball never made it into the Arch Linux provided binaries, as the build script was configured to only inject the bad code in Debian/Fedora based package build environments.
>>
went to nixos after arch. then tried use debian with nix installed. nixpkgs has turned out to be a great AUR replacement for my needs. using hyprland-git on debian trixie. only thing i cant use is the hyprland screen locker because debian patches its polkit to use a different syscall from every other linux distribution uses for some reason. so i used swaylock. if i ever go back to arch. it will not be using the AUR but with nixpkgs.
>>
>>109424122
whaddap my nixxer
let's post pictures of our buttwholes as is customary
>>
>>109424122
That's comparing apples to oranges, nixpkgs is the official Nix repo, the AUR is an unmoderated user repository
>>
>>109424146
you first
>>109424147
and its great. and you can use it on any linux distro. the system level shit needs some workarounds if you absolutely need it. but if i needed the nix system level shit, id just install nixos.
>>
>>109419858
all arch problems can be fixed by only using pacman
>>
>>109419858
whats the point of using the AUR?
can those tards not just bulid from source?
>>
>>109421568
>This has to be because Steam is easy to grab personal information because workshop has yet to fix the virus problem.
Wait what? Is the workshop compromised?

Makes me glad I haven't used Steam in years.
>>
>>109421568
with the pace that valve updates steamos nothing will make it through
also a great reason to use the flatpak version of steam
>>
>>109424232
If you're willing to build from source then surely auditing a pkgbuild is no big deal.
>>
>>109424325
even for people who know how to build from source, using a package manager is just more convenient. its just unfortunate that the AUR had basically no moderation or even a vetting process. luckily that the ABS is not the only source based package manager.
>>
>>109419858
I can't take this clownery anymore.
I think I will switch to gentoo.
>>
File: 1784477118476870.jpg (69 KB, 450x675)
69 KB JPG
>>109419858
good thing I only have gzdoom installed
>>
File: file.png (261 KB, 496x496)
261 KB PNG
>>109424421
DEPRECATED
>>
>>109423247
>>instead of just a normal version of debian without the faggotry
that's just mint, you retarded nigger faggot
>>
>>109420311
Valve doesn't use AUR in any capacity, retard. If valve wants a package in arch repos it's happening.
>>
>>109424259
Workshop is not compromised, games have vulnerabilities and some allow running arbitrary code. It's possible to distribute this code using workshop mods if the game supports workshop and allows mods to run arbitrary code with full system access.
>>
File: 1781296547872004.png (303 KB, 900x751)
303 KB PNG
slow and steady wins the race.
>>
>>109425128
>adds faggotry
>thinks that's debian sans faggotry
you sir, are the homosexual ficus.
>>
>>109420034
they're not though. all of the tech youtubers telling people to switch to linux for gaming are telling them to use bazzite. that's fedora based.
>>
>>109424386
literally the best linux distro on the planet, unironically. you won't regret your choice.
>>
>>109420214
good to see my AUR helper wrapper that tracks the malicious packages and annotates them on searches with yay, pacaur, or paru is picking up the new wave of malicious packages like it's supposed to.
>>
>>109425302
How does it determine what's unsafe? Is there an API somewhere or it just has a hardcoded list that has to be constantly updated?
>>
>>109423578
It's good to see they put all that on one page. I already knew all of that but it's good to have a resource to refer to.

The fact that Flathub has not had a single compromised application published speaks for itself.
>>
>>109425307
hardcoded list that is constantly updated, with a cronjob that runs a LLM and has it search every 6 hours for reports of new malicious packages, then it updates the lists. users can type 'aur_safety update' to grab the most recent version of the lists (i encourage them to do it at least once a day) from the git repo so they don't have to pull and re-install the package all over again
>>
>>109423977
That's not as good as it sounds when you realise that the compromised code WOULD have made it there if the attacker didn't actively disable it in certain circumstances.
>>
File: 1785445430779063.png (288 KB, 640x360)
288 KB PNG
>>109419858
Arch Linux is not a serious distro. Most Archbabbies are probably running around with an exceedingly barebones installation and zero thought of hardening or security because doing anything like this on Arch requires you to be a Linux admin (or thereabouts) and treating your install like a full time job. Installing Arch through the installation instructions leaves you with the single most basic Linux install you can possibly have, and yet these posers think it makes them some kind of h4x0r for doing so.

>inb4 "da aur isn't technically part of arch"
Yeah, it's not, and if you were to not count it, Arch's package repositories would be miniscule. That's why people use it. Because it is required for so much shit in Arch, because the base package repos are so tiny. The Aur is a malware repository masquerading as a package repo, Anne Frank-ly it's amazing it took this long to be abused like this.
>>
>>109419858
societal trust is eroding and you're laughing
>>
>>109421601
You obviously thought wrong
>>
>>109420041
>and saying socialism works
does he have downs syndrome?
>>
>>109425318
>hardcoded list that is constantly updated
where is this? I downloaded a few packages but I need to know for sure
>>
>>109419858
I love Mint.
>>
>>109419858
>Arch Linux AUR Under Another Wave Of Malicious Packages
fake news faggot
>>
>>109419858
Who is attacking the AUR with malware and why?
>>
>>109419858
>user repository
>surprised there is malware
are you retarded?
you do not have to use the aur and if you do you are supposed to check the pkgbuilds.
>>
>>109425557
using arch is basically being a sysadmin for your pc
when i started using arch other arch users told me that stuff like apparmor or a firewall were not necessary lol
>>
I don't give a shit, I am using Arch for 8 years or so and never needed the AUR.
>>
CasshewsOS users don't have to worry because they have a repository that replaces the AUR for most needs
>>
>>109420941
Doesn't OBS work properly?
>>
>>109426482
>when i started using arch other arch users told me that stuff like apparmor or a firewall were not necessary lol
Yeah see, so many of them are dumb. They think they're hot shot but their installs are the most basic, rickety thing ever. Arch can't even install with secure boot turned on, and most of its users probably don't even know what secure boot does.
>>
>arch is for experienced users, you should not what you do, for an example knowing what you install
>hurr durr i use arch btw

Typical.
>>
>>109421012
are there other methods the aur can be compromised besides pkgbuilds?
>>
>>109420034
Linux users will have to install an antivirus just like in windows. Oh, the irony
>>
>>109426500
CachyOS is truly the best. I don't know why more people don't use it.
>>
>>109426710
Because "it reeks of gaymer, ick"
>>
>>109426710
This but unironically. It's measurably faster than other distros (sans Gentoo if you coompile the same way CachyOS does) and it just werks.
>>
>>109426710
Cachytranny is the new manjaro
>>
>>109419858
anyone has some AUR package that can scan if i installed infected malware aur user package?
or some terminal cli command?
>>
>>109425274
>>thinks that's debian sans faggotry
it is factual that debian comes with all the faggotry and mint has to avoid it like its a carcinogen
go check if your debshit has pushed for more DEI internships to cover up for their pedophile leaders, retarded slave.
>>
File: 1785340372361267.jpg (36 KB, 401x498)
36 KB JPG
>>109426482
you 100% already have iptables/nftables already installed when you installed arch. the default settings are fine
>>109426552
you can easily enable secure boot on arch, sbctl is in the repo all you have to do is put secure boot into setup mode and follow the wiki it details how to use sbctl, after that anytime you run mkinitcpio it'll check if you're signed
>>
>>109420012
It doesn't.
>>
>>109426941
>you 100% already have iptables/nftables already installed when you installed arch. the default settings are fine
are they?
>>
File: cachytranny.jpg (1.28 MB, 3127x1800)
1.28 MB JPG
>>109426710
>>109426717
>>109426723
>>109426798
>cackyOS
>>
>>109420118
>the only thing that kept Linux as safe from viruses as it used to be was the fact that barely anyone used it
No, it's because it's inherently more secure than Microsoft operating systems. You think servers aren't also targets of viruses?
>>
>>109420941
They should shut it down. The AUR was always a fundamentally terrible idea.
>>
>>109425268
>It’s not hacked
>It’s hacked
Steam is no longer safe anon, their “Trust me bro” nonsense lead to the arrest of criminals by the FBI. All because Steam lied about safety. Now you here defending Valve for lying.
>>
>>109420956
They could do a [Y/N] prompt for every directive in it.
>>
>>109421844
For one-off stuff just download the source and put it in /opt/ yourself. No need to bother with the package manager.
>>
>>109425319
It also only worked with Systemd and an increasingly large number of "arch" users are really on Artix.
>>
>>109427143
M$ has like 50% of the server maket also.
>>
>>109427442
>>109427143
>>109420118
It's because normally the only way you install packages is you build them from the source or you wait for repo maintainers to look at new releases, build them, package them and distribute them.

AUR leapfrogs that for the sake of convenience with the same consequences you have one Windows. IMO it's good to have the option but you have to understand the risks and how to mitigate them. "Just don't" is good general advice.
>>
>>109427437
the package manager is just for easier updating. i can mass check and update any packages i want
>>
>>109427462
How often are you updating obscure unpackaged software that git pull && make && sudo make install is too inconvenient?
>>
>>109427472
>i'll completely add words to your post that you didnt say and quesiton you based on my own addtion
>>
Man fuck Arch, I'm going to install NixOS
>>
>>109427501
I can't believe president Nixon has his own linux distro.
>>
i looked at the affected packages and you have to be a retard to install those
>>
>>109427621
are you going to keep using arch after this shitshow?
>>
>>109427629
yes?
>oh no, le hecking openssl1.1-bin got hijacked!!!
why were you installing this in the first place?
>>
>>109427621
It's still a big step to go from completely safe to something a retard could hurt themselves with.
It was always a theoretical issue but to have it realized is a big deal.
>>
genuinely comical seeing arch trannies telling us that the AUR isn't important and that they never pushed it as the reason to switch to arch
>>
>>109427682
its not about that
of course im never going to install random aur packages
but it looks really bad for arch, constantly be on the news about malware "attacks"
the arch maintainers need to take it seriously, not whatever the fuck they did after last months wave
>>
>>109424122
this is how good you could have it if you weren't so surveillancephobic /g/
>>
>>109419858
>spam and profanities
Not profanities! *clutches balls*
>>
>>109426482
Why do you need apparmor and firewall when your computer isn't even connected to the Internet?
>>
File: 1784502370176240.png (34 KB, 544x410)
34 KB PNG
>>109419858
just install gentoo
>>
>>109419858
i use botnet btw
>>
>>109419858
The malware only started after cachyOS
>>
File: hadenough.png (90 KB, 563x386)
90 KB PNG
UH OH
>>
>>109427442
Got a source for that? I don't believe you.
>>
>>109420214
>All literally trash packages
>>
>>109428705
>Arch loses it's reddit moderator
Oh, the horror! I'm sure they'll manage without him.
>>
>>109422279
Is BSD next on the chopblock?
>>
>>109419858
this is what happens when you treat a gentoo-style hacker distro as a production one
the standard (pre-2021) advice has always been to treat the aur as a starting point for your own pkgbuilds that you personally manage, akin to how user overlays are supposed to be forked for your own needs
most people using arch (and especially its derivatives) are better served on fedora
>>
Is Fedora the only sane alternative to Arch? Debian is too slow.
>>
>>109419858
how hard is it to simply not let anyone take over orphaned packages without telling any potential downloaders that it changed ownership
freeze that specific package forever, whoever takes it over gets a renamed version
if someone wants it as a dependency they'll test it before requiring it
>>
>>109419858
>be me, take up hobby
>the internet: [this hobby] has been infiltrated by XYZ and is detrimental to YOU EXPLICITLY
>me: *leave hobby*
>me: *take up new unrelated hobby*
>the internet: [this hobby] has been infiltrated by XYZ and is detrimental to YOU EXPLICITLY
>be me: *leave hobby*
>be me: *take up new, completely unrelated hobby, which i invented myself*
>somehow, the internet: [THAT NEW HOBBY WHICH ONLY YOU KNOW ABOUT] IS DETRIMENTAL TO YOU EXPLICITLY, STOP IT BECAUSE XYZ

yeah, i dont care, i'm going to continue using arch linux, unless i find a new OS that fits my taste.

>here's why the way you're doing [your hobby] is wrong
>you NEVER knew about these things about [your hobby]
its the same clickbait meta that youtube content creators used these last 15+ years.

this is why i hate all forms of click based content.
>>
>>109426391
she's cute, but i prefer henya.
>>
>>109429501
>whoever takes it over gets a renamed version
that's formally known as a "fork"
>>
>>109419858
looks like im staying on atomic fedora
>>
>>109419858
arch being called a meme for a reason
>>
>>109419858
I am convinced Fedora and Fedora derived distros are doing this because Fedora and it's derivatives are losing popularity to Arch based distros like CachyOS.
>>
>>109419858
desu I pretty much never use anything on AUR any more anyway I used to years ago, but if your only option is the AUR normally there a better alternative.
>>
File: 1755023079797975.jpg (50 KB, 960x504)
50 KB JPG
Fuck this.
Is there any tool to check if I have the malware or not?
How did it even get back?
Should I update now or is it still compromised?
>>
>>109425557
why are all arch haters so misinformed and retarded?
>>
>>109427331
You are retarded. Nobody hacked workshop. The mods were valid and uploaded through normal means, they even contained no suspicious files. The game just gave mods the ability to run arbitrary power shell commands.
The only practical solution valve has is to delete workshop. Or alternatively make workshop support exclusive to a very small number of trusted and vetted games. Clearly this game shouldn't be allowed to be modded.
>>
>>109429358
yeah i was going to learn to to write my own PKGBUILDs
but if it gets to that point, isnt it better to use a distro with bigger repositories, or where third party software makes official packages for your distro (deb, rpm)
>>
>>109432203
Someone did idiot: https://escorenews.com/en/csgo/news/53826-valve-fixed-critical-exploit-that-allowed-to-access-cs2-inventory-via-workshop-maps

Valve clearly lied about fixing workshop maps and mods. Stop believing in their lies.
>>
>>109426842
>getting your info from Jewduck
Give me one reason to care about your opinion.
>>
>>109432502
Cs2 is a completely different game turbo retard. This is like saying Microsoft fixing a bug in windows didn't fix it in Linux.
>>
>>109430404
Red Hat doesn't care because, much like Canonical with Ubuntu, they already dominate the spaces that matter to them (enterprise). They would give less of a shit about the end user, which is why Fedora is stuck as RHEL's beta testing grounds.
>>
>>109419858
>Why are people panicking about this?
>This is fucking retarded.
Like, check the fucking PKGBUILD, dumbass.
But if you by accident forget to read it, and you may have installed malware,
>run the command: echo "Affected Packages Found:"; comm -12 <(pacman -Qq | sort) <(curl -s https://cscs.pastes.sh/raw/aurvulnlist20260611.txt | sort) | { read -r l && printf '%s\n' "$l" || echo "None. No known compromised packages are installed."; } to make sure you didn't install malware.
>>
>>109432515
That happened too: https://linuxsecurity.com/news/vendors-products/windows-update-fixes-linux-dual-boot-boot-issues

You’re stupid
>>
>>109432855
Oh god, you're too retarded to be real. This isn't even analogous, who the fuck was talking about dual booting? Fuck off dude, it's exhausting to talk to someone as dim as you.
>>
File: 1775075872205793.jpg (58 KB, 686x386)
58 KB JPG
>>109428354
this
>>
>>109420012
Because C is shit and AIs are finding new bugs everyday.
>>
>>109425240
>Valve
Yeah, very cute misdirection, you stupid fuck.
>>
>>109419858
AUR malware checking tool, will determine if you have been fucked.

https://github.com/lenucksi/aur-malware-check
>>
>>109432542
I'm not fucking curling anything
>>
>>109420072
>is buying forests saying
>look we have no crime because of socialism!
Are you schizo or do you have a rational reason for stringing together two unrelated things?
>>
File: 1679295853826080.png (66 KB, 443x399)
66 KB PNG
>>109419858
The dipshit Arch devs/community think that this is some survival of the fittest thing, and celebrate when anyone runs malware through software they host and encourage people to use. I don't think I've ever seen an archfag happier than when they can chastise/put down anyone asking for help with this sort of thing
>Did you see the warning on the arch wiki?
>Did you READ the pkgbuild? Huh? Did you read it? You DESERVE it you little bitch

etc. I clearly remember the losers in #archlinux on irc banning people just respectfully asking if anything was going to be done to block AUR while the last attack in June was ongoing. A nasty, toxic community where the members feel glee at talking down to others (when the vast majority of these people are just retards that copy/paste shit from a wiki and rice desktops).

I wish Arch in its current form dies and is replaced by a Valve led fork of it.
>>
>>109434097
AUR does not host software. It hosts pkgbuilds.
>>
>>109419858
it’s only going to get worse when ai bots are hammering it 24/7 until the end of time with malware
>>
>>109434110
Oh look mimsy, another retard! The AUR is a git repo you chucklefuck, and therefore it can and does host binaries. The latest attack includes packages that add a malware binary which is called from the PKGBUILD.

Why am I not surprised that an arch defender doesn't know what they're talking about?
>>
>>109425318
Can you post the repo? The arch devs / community seem to think posting an official known list is like pulling fingernails or something so they absolutely expect you to dig around in the mailing list or reddit or wherever the fuck
>>
>>109432542
>Man who can't read chastises others for not being able to pick out tiny details in a crappy script file
Many such cases! Try reading these words: This is a new attack, so your vuln list from the last one is not useful.
>>
>>109419858
>use meme, tranny coded distro
>get hacked
>>
>>109419858
I hope all the gaymer manchildren on cachyos got hacked in the ass
>>
>>109420163
>/pol/ack le vent
>>
>>109429391
Debian testing, but it's technically a development branch and doesn't get dedicated security support
>>
>>109431768
Explain which parts of that post are wrong
>>
>>109419858
My gentoo system doesn't have this problem.
>>
>>109423247
what would you remove from debian to remove "the faggotry"?
There's nothing in it.
Unless you mean SunnyDlight but then you'd just run Devuan.
>>
>>109434688
everyone knows that gentoo users are compiling 24/7 instead of actually using their computers so there is no point in such attacks
>>
>>109419858
Why are Dindus attacking Arch ? is it really about the normies ?
>>
>>109435234
It takes like 5 minutes for anything that isn't a Chromium or based on Chromium like qtwebegnine
>>
>>109419858
Tye concept of arch linux is retarded in the first place. Who needs to be forced to update everything every few days? Even Microsoft pushes out updates once a month.
>>
Fuck this shit.

Just finished transitioning my AUR packages over to a staged local package repository built with makepkg and repo-add, and removed paru and yay. Now I can update and audit them at my own cadence.

Vibe coded some scripts to automate the process.
>>
>>109435259
You mean webkit?
>>
>>109423247
You have filtered yourself as a moron. Debian is one of the most inclusive open source projects. Hahahahaha you fucking retard you should join the Debian Women's mailing list, I heard they allow troons like you.
>>
>>109419858
Been thinking of jumping distros. Anyone use PikaOS?
>>
>>109431543
Halp?
>>
>>109427103
i want the person who took this photo to die. Immediately.
>>
File: IMG_0674.gif (863 KB, 320x176)
863 KB GIF
>>109432932
Getting offended because you ask if Microsoft did something wrong to Linux by updating their operating system and anon delivered is why your whiny behavior isn’t acceptable in /g/ return to /v/ cultist Sheep.
>>
>>109419858
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/P4WIRHTFNH2YZWQHGBAKQWX5YOAFIDLY/
Anyone else got malware from these?
>>
Being blamed for letting a PKGBUILD slip something nefarious through is like blaming someone for not spotting every possible mole on their body that could be cancerous. Imagine you get diagnosed with skin cancer and the derm/oncologist tells you "Hey fuck you, you didn't catch this one mole so you deserve this"
>>
File: 1779241593533296.png (3.44 MB, 1344x1728)
3.44 MB PNG
>>109426552
>Arch can't even install with secure boot turned on
this is wrong, the installation image that they distribute is not signed, but you can sign it with your own certificate to make it boot
>most of its users probably don't even know what secure boot does
at least secure boot is covered in detail in the arch wiki
>>
sudo pacman -Syu

not my problem
>>
File: 1765927643861289.png (82 KB, 1280x640)
82 KB PNG
I'm really considering moving to NixOS or using system-manager with Arch as base.
>>
>>109419858
If linux distributions and package managers won't adapt some sort of LLM based antivirus-filechecker, entire linux is kill.
>>
File: 1785436096715107.gif (470 KB, 220x220)
470 KB GIF
>>109438893
>>
>>109419858
AUR, more like OUCH
>>
>install random unverified software from the internet
>get hacked
wtf how could arch do this to me??
>>
>>109437407
Yeah PKGBUILDs have to be proof-engineered. Making sure that they are safe is something that you need a doctorate or college degree in order to do because of how complicated they are.
>>
>>109435542
yay will tell you if a package has been orphaned or adopted.
>>
>>109419858
Glad II moved to Fedora. At least for now.
>>
>>109419985
Wasn't their default repository completely separate from AUR?
>>
>>109444344
nigger...
>>
File: 1000025765.jpg (25 KB, 380x404)
25 KB JPG
I'm on cachyos but I used the AUR to install things like chrome because it wasn't in pacman
am I retarded
>>
File: images (69).jpg (26 KB, 512x384)
26 KB JPG
You wanted more people to adopt Linux? You got your wish granted
>>
>>109444358
>>109444364
was a reply to you before you deleted the post
>>
>>109444651
can you answer my question
>>
File: 20260803_025346.jpg (258 KB, 2047x651)
258 KB JPG
I'm safe right?
How do I even check to make sure I'm not getting pwned when I download shit?
>>
>>109444364
I mean my gut instinct is to say yes, you are retarded. If you aren't verifying the pkgbuilds then yes for sure.
>>
>>109444877 (me)
I also want to say that Arch being marketed as a starting distro by retarded influencers like pewdiepie are a lot of the reason this AUR shit is a big deal. People like >>109444680 don't understand what they're getting into. Arch is an enthusiast's distro and you really should be a programmer or something similar if you want to use it.

To answer your question, here is the list of affected packages >>109420214
>>
>>109444877
How do you verify them?
How are you supposed to install things that aren't in pacman if the AUR isn't safe?
>>
i never trusted the AUR and had like 5 packages installed from it
i always checked the PKGBUILD and checked the diffs on every update
how hard would be to start writing my own PKBUILDs for the few packages i might need that are not on the arch repos?
>>
>>109431543
If you don't know, assume you have malware, format and reinstall, then don't use AUR. Or install an actual distro instead.
>>
>>109434560
Just run Sid.
>>
>>109439524
Because Arch has become a popular choice with newbs and gamers for some reason, when it's really a neckbeard hobbyist OS and they should be using Bazzite or even Mint instead. The AUR has also been shilled hard as a selling point where you can get any package you want, glossing over the fact it's a pile of unvetted shit.
>>
On a long enough timeline I think this is going to happen to every distro eventually, unless you are running Gentoo and have the time to review every single diff.
I'm wondering how best I can protect myself for when it eventually happens to mine.
Reduce package count to the absolute minimum required for QEMU, and then run everything else in a VM?
>>
>>109445804
No, this is not going to be the future of all distros because other repositories have actual testing and review. Arch has been offloading responsibility and labor to their users for years, the distro proud itself on having a setup script, it only supports x86, and don't even release images with a desktop environment. Most distros do what Arch do, but not the other way around. It's a niche distro that finally is getting what it deserves for not giving a damn to setup proper infrastructure. If you do care about the best protection, get openBSD or QubeOS.
>>
>>109445838
Who is reviewing? Do you know them personally?
I'm not comfortable betting my life savings, and my business, on people that I don't know, working for free, to do their job perfectly for an infinite amount of time.
It won't happen the same way as this attack, but it could still happen via bribery, blackmail, social engineering, negligence of the reviewers, attacker getting lucky, who knows.
>>
>>109445897
By that logic then don't go outside at all because something may happen to you.
>>
>>109445920
Do you often carry your life savings around with you outside?
>>
going to ubuntu. tired of this shit
>>
how do I know if an aur package is malicious or not?
>>
>>109436216
why? lmao
it was me btw
>>
>>109445897
>It won't happen the same way as this attack
It won't happen at all. It could theoretically happen, but it won't
>>
How to avoid this problem:

Add the following to your bashrc/zshrc
#before every update, run
archinfo(){
yay -Pww
yay -Ps
}
#read the news and notice what packages that yay -Ps reports as orphaned. Either remove those packages or add the to the ignore list in pacman.conf, like:
#IgnorePkg = <orphaned package> <orphaned package>

#then, update
archupdate(){
#sudo reflector ...
yay -Syyu
#some other package manager, like cargo or cpanm
}
>>
>>109420941
Limiting typo squatting and orphaned packages should generally do the trick.
>>
>>109447314
i use paru just because it makes -Pww completely unnecessary. i don't know why yay doesn't implement NewsOnUpgrade. you can also set FileManager to something like lf and if you keep old PKGBUILDs, you can compare diffs.
>>
File: 2026-08-03_11-58.jpg (352 KB, 891x1802)
352 KB JPG
>>109448884
>>
>>109448884
yay shows me the diff for every package I update and the pkgbuild for every package I install. I don't use a terminal file manager because I'm not a larper.
>>
>>109448907
>feature complete
so it'll work forever with no breaking changes?

>>109448925
i don't normally use one either, i only use it to look at paru's diffs since it's fast and the preview pane is useful. i'm already in the terminal when i update, i might as well stay in it.
>>
>>109448948
If it "worked forever," then they wouldn't need to do 6 months worth of bug fixes. You don't say "use paru-git even though that's the thing you're saying isn't working correctly. It's feature complete. We'll fix it."
>>
>>109448884
>i don't know why yay doesn't implement NewsOnUpgrade
yay -Pww
yay -Syyu
wow! So hard to figure out. That should totally be a setting.
>>
>>109444286
CachyOS? I mean just like Arch you can use AUR if you want. Some retarded gaymers were doing it all the time before this shit happened
>>
File: 1779378692983050.jpg (35 KB, 375x375)
35 KB JPG
>>109419858
>just read the pkgbuild
what's the problem, exactly?
>>
>>109449737
op can’t read
>>
>>109445771
Yeah because CachyOS is genuinely a great Distro, that's why people use it
Bazzite is good as well but some may not like an immutable Distro.
>>
>>109450122
I've never used Cachy but if they're taking Arch and turning it from a tinkertranny hobbyist distro into something useable then fair enough. But that's not what I'm referring to. The meme of noobs using Arch as some mainstream gaming distro predates Cachy.
>>
File: 1611247163550.jpg (76 KB, 517x396)
76 KB JPG
>>109434097
Yeah, there is lots of reddit tier toxic positivity in Arch, but its generally true that you need to know your shit and have some common sense before you install Arch and download stuff from AUR. The Arch install wizard, and CachyOS-SteamOS have been more of a net negative than good for Arch itself though.
That being said, a major problem is that Arch users and contributors have been regurgitating these "read the pkgbuild" sayings for so long, they have either forgotten how to harden their OS with the simple, logic-based solutions, they are just that lazy and blame the end user as a comfortable deflection, or maybe this commie philosophy of Arch doesnt work as good as it is supposed to be.
It took the previous AUR infestation for the AUR maintainers to finally stop allowing ppl with burner mails to adopt orphaned packages. Like why the fuck they allowed that in the age of bots and vibecoders? That shit alone says alot about the people who run Arch and AUR.
God only knows what other retarded ideas they apply or what elephants in the room they dont adress as they run this Arch-AUR shit show
>>
if i want to install shit from the AUR that isn't in any other package manager, but the AUR isn't safe, what am I supposed to do?
are flatpaks better?
>>
Just get Nobara
>>
>>109451850
Learn how to compile and build packages yourself. The Aur is just a helper, let it help you build them yourself. Dont rely on Aur helper software or the Aur, learn to use makepkg instead and build packages inside an archlinux docker container or something similar.
>>
>>109447082
there are two aur package scanners, one llm backed and one not
pick one or both and write a little wrapper for yay or whatever you use
>>
>>109451982
What is actually involved in doing that?
>>109452153
What are they called?
>>
>>109452269
aur-scanner
aurscan-manticore-release-git
>>
>>109452153
is yay or paru better?
>>
>>109452382
paru is unmaintained
>>
>>109452269
>What is actually involved in doing that?
see the arch wiki, start with "makepkg".
PKGBUILD files contain everything you need from the aur.
Im vetting the PKGBUILD text files with upstream devs manually, checksums and versioning.
Its as simple as `makepkg -sic` in the same directory as the PKGBUILD text file.
So say you want google-chrome, download the pkgbuild into a directory, say google-chrome, cd into that directory and run `makepkg -sic` after you have vetted the PKGBUILD text file and the contents it wants to download to your machine, like are the urls correct, do that checksums match and if they dont edit the PKGBUILD to match the upstream checksums and urls etc.
Years ago we all built programs from svn's etc, makepkg just makes it easier, even easier when you use an AUR helper program.
But the risks involved now are getting ridiculous, so its time to revert to the old ways and maybe just install gentoo.
>>
>>109453075
* To add, you should know what the pkgbuild wants to do to.
Like what are the build() and package() commands doing, do they look right?
This is why normies have no idea when it comes to building packages from source and think its just like installing an .exe
>>
>>109420941
You can't fix it.
AUR is user submitted packages and that's just antithetical to security and maintainability. For user packages, they have to be created by the site's system administrator in house. Only packages maintained by the distribution can be shared with other site installations.
Shut it down, and people should move to a proper professional distribution like Red Hate Enterprise Linux with a proper support contract.
>>
>yet another psyop from The Powers That Be to get the AUR taken away from us
>>
I use paru for the AUR
Should I switch to yay? is it better?
>>
>>109454033
yes. paru is unmaintained. read the repos from time to time.
>>
>>109453261
>people should move to a proper professional distribution like Red Hate Enterprise Linux with a proper support contract.
Imagine paying $180 for a redhat licence when i can download and install almalinux or rockylinux.
I wont get the same level of customer support but im not a retard either.
>>
>>109454310
is there anything wrong with it that needs to be fixed?
I chose it over yay because it uses the same syntax as pacman, and apparently it runs faster
the pacman build for paru is somewhat recent
>>
Why is google chrome not in the official repository?
Should I switch to the flatpak?
>>
>>109419858
>aur
nobody cares.
it's summer, there's always some scriptkiddie group getting into some shenanigans. has happened without fail every summer for over a decade.
>>
>>109420012
>why does linux need to be updooted every day i dont get it
linux doesn't need to be updated if your machine just works.
>>
File: pikaur.png (546 KB, 1344x2086)
546 KB PNG
been using Pikaur for years, shows you the diff on changes and I really like the version highlight
>>
reading this thread is pure ragebait, do niggers really not know how to compile their own software?
>>
HAHAHAHAHAHAHA AHAHAHAHAHAHAHAAH OPEN SOOOOOOOOOOOOOORES!!!!!!!!!!!
>>
>>109451850
Compile it yourself, use the flatpak/appimage if available or use an APT distro and just get the .deb file
>>
>>109456649
How do you compile it yourself?
Should I switch from AUR Google Chrome to the flatpak?
>>
>>109456656
>Chrome
You can't compile that. Just use the flatpak.
>>
>>109444364
>>109445008
>How are you supposed to install things that aren't in pacman if the AUR isn't safe?
By not using a DIY tinker distro with the sole purpose of tinkering. If you don't want, know or care how to build your own system from scratch then why are you using Arch? CachyOS is just Arch with a better installer (which already defeats the whole purpose of using Arch). Arch is meant to be a model kit that you assemble yourself.

Use a real distro that is meant to be used which actually has all the packages in it's main repo instead of a shitty user repo filled with malware. The reason the AUR exists in the first place is because the main Arch repos barely have any packages in them.
>>
>>109456672
What reason do I have to bother switching over to the flatpak if the AUR for it isn't compromised?
>>
>>109456694
>Use a real distro that is meant to be used
such as?
I daily drove steamOS for years which is why I went with Cachy
>>
>>109456705
Either Ubuntu or Fedora, everything else is just a meaningless reskin of those two anyway. Maybe Debian if you really hate Canonical for some reason and don't care about outdated packages. Choose the spin with the desktop environment you want and be done with it. Everything else is just a downgrade in terms of package availability. Use flatpaks, snaps or appimages for anything else.

The reason SteamOS uses Arch as a base is because Valve can freeze the packages at any time they want and not be dependent on the release cycle of another distro. But as a user this doesn't matter in any way. ChromeOS uses Gentoo as a base for similar reasons and no cares about it as well.
>>
>literally do anything except learning how to read the PKGBUILD
Why are zoomers like this?
>>
File: d.png (129 KB, 1628x702)
129 KB PNG
>>109456748
Sid is pretty comfy desu
>>
>>109445897
Every piece of open source software can get hacked too and it happened before. One developer gets his credentials stolen and the hacker pushes malware in a commit without anyone realizing. Or the hacker puts some backdoor into the software with a PR without anyone realizing. Or maybe the software was compromised from the very beginning and no one ever checked the source code.

It's a bit scary to think about how fragile this whole system is. Ideally you would use a minimal amount of software made by a large group with lots of eyes on it that get paid for their work and only install it from the developers themselves and not rely on third party packaging. But the repo system of Linux doesn't allow this.
>>
File: 1754771187718354.png (41 KB, 861x744)
41 KB PNG
>>109456753
>never seen a pkgbuild in my life
>ask chatgpt
I ain't reading all that mumbo jumbo shit nerd
>>
>>109456900
Saar
>>
File: 1536317902040.png (500 KB, 640x480)
500 KB PNG
>>109419858
Why not just use pacman as your main and nix package manager as your secondary? And there's also flatpak and appimages. You don't even need the AUR at all. Why do anons like to hurt themselves? :(
>>
>>109456748
but I'm already familiar with arch
I don't want to switch
>>
>>109456994
I've never even heard of nix
can I use it on Arch
there's stuff I wanted to use that's only in the AUR
>>
>>109456900
>use nerd distro for nerds
>be surprised about nerd shit inside his nerd distro
When will people finally understand that the sole purpose of Arch is too read meaningless junk like this because nerds enjoy it? The whole install process is about reading some badly written wiki that tells you what commands you need to copy and paste and reading up on the fine details of bootloaders and other nonsense. I can't fathom how it got popular in the first place.
>>
>>109457039
Yes you can use Nix on Arch, but isn't Nix also user run?
>>
>>109457018
>but I'm already familiar with arch
In what way? Every distro functions the same since they all use the exact same software stack with the exception of the package manager. The only difference you will notice is that you have a system that actually works with way more software available.
>>
>>109456695
You're the one asking what to use instead of the AUR, but to answer your question I would never consider installing software from something as fundamentally flawed as the AUR, but that's your decision to make.
>>109456748
This echoes my own opinion. I've played with Arch in a VM many times, but I'd never install it on my machine. Personally I use Debian, but I've previously used Ubuntu and Fedora.
>>
>>109457065
I don't want to have to relarn all the terminal nomenclature
>>
>>109456830
isnt debian sid worse than arch?
its the devlopment branch and they dont gurantee security
>>
>>109457048
Nix:
Changes require a Pull Request (PR) on GitHub.
PRs are reviewed by multiple maintainers who specialize in that area.
A PR can take days or weeks to be merged.
Every PR submitted to nixpkgs is automatically tested by Hydra, a massive, automated build farm.
The package is built in an isolated sandbox on Nix's build farm.
The sandbox has no network access and cannot read your home folder.
Each package has one or more designated maintainers who keep an eye on it.

So NIx has safety measures while the AUR doesn't. I just vibeposted this so take that for what you will.
>>
>>109457092
You wouldn't need to use the terminal in the first place if you would just use one of those two distros and I doubt there is anything else you need the terminal for. On Arch based distros you need to install packages through the terminal because pacman doesn't integrate into KDE Discover for example. All other terminal commands are the same since they all use the same command line tools.

apt and dnf are also way more sensible in their naming like "apt uninstall firefox" instead of "pacman -Rns firefox".
>>
>>109457209
well I've gotten somewhat used to using the terminal because I like being able to see exactly what's happening and knowing exactly what I'm doing
I've already gotten comfortable with CachyOS on my new PC and don't want to fucking start start all over again
>>
>>109457154
>its the devlopment branch
True
>and they dont gurantee security
Security updates aren't guaranteed to be timely. I would not run it on servers. But for example Firefox is updated very quickly, almost always faster than Fedora.
>>
>>109457247
Nta, you'll have to at some point unless you go with an established distro. Meme distros like cachy come and go
>>
>>109427143
>No, it's because it's inherently more secure than Microsoft operating systems.
Its been known for decades that Linux is only "inherently safer" through usage being so low that targeting them was a waste of time. OSX was the same way, until usage spiked due to being popular in universities and colleges which brought an onslaught of malware.
>You think servers aren't also targets of viruses?
The vast majority of server attacks are done without any malware at all, and Linux servers still do get attacked.
>>
>>109457302
>meme distros
what is with retards and attaching meaningless buzzwords to shit they don't like
shut the fuck up
>>
Isn’t the main problem with AUR that, when you use it, you should always check the pkgbuild and not just go ahead and install it straight away?



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.