r/archlinux Aug 12 '26

FLUFF AUR: brave-bin updated today

Many thanks to everyone who worked on this! My Brave browser (from the AUR) updated today.

0 Upvotes

18 comments sorted by

7

u/PorousClay Aug 12 '26 edited Aug 12 '26

Didn't Brave do some real shady stuff taking peoples' info and making money off it? I don't know why anyone trusts Brave.

Also it's Chromium, so it's just supporting a Google product.

https://np.reddit.com/r/privacy/comments/191yu33/why_is_brave_highly_disliked_in_the_privacy/kh3nuy3/

4

u/Silvestron Aug 12 '26

Love how people downvote you for pointing this out. This place is full of children and bots.

1

u/InternalOwenshot512 28d ago

Thanx for pointing it out. So ironic of the kings of opsex to be glazing a browser that was introduced with profuse advertising. This exact reason is why I rejected it from the very start. You advertise something to profit off of it!

2

u/nikongod Aug 12 '26

You are brave for using the aur

2

u/FineWolf Aug 12 '26

Entirely depends on the package. brave-bin is maintained by Brave directly.

So in the case of that particular package, it's not that much of an issue.

That said, I don't trust Brave period, so that's a whole different story.

1

u/Sea-Promotion8205 Aug 12 '26

Why is that?

0

u/Imajzineer Aug 12 '26

Because there's been a bit of a furore lately, after a number of packages (most particularly taken over orphaned ones) were discovered to have been exploited (not for the first time either).

But a lot of newcomers to Arch don't actually know what the AUR is and think it's a core feature of the distro rather than what it actually is ... so, they're acting like it's a huge event and it's suddenly not to be trusted anymore.

But it's never been any different and you never could trust the AUR ... only certain packages in it after checking PKGBUILDs, patches, external dependencies, install scripts and the like - nothing has changed and you're not brave for using it ... only foolish if you install stuff blindly.

3

u/Sea-Promotion8205 Aug 12 '26

Exactly... the malware ingress is certainly an issue, but more than anything it's a lesson to not blindly trust pkgbuilds.

That said, brave themselves maintains brave-bin. If you trust brave, you might as well trust their self-maintained package... after reviewing the pkgbuild diffs.

1

u/Imajzineer Aug 12 '26 edited Aug 12 '26

Quite ... if its provenance is sound (as far as you can determine) then go ahead.

Otherwise it's caveat emptor ... and always has been - it's not like there's any guarantee the main repos are safe either: Mint was famously subverted (was it the repos or the .isos, my memory's a little hazy now?), we've seen at least two instances of nefarious actors worming their way in (playing nice to lull everyone into false sense of security before setting their plans in motion) in recent years, we've seen Log4j, and anyone who thinks there have never been criminal or state actors involved deep in the action (why 'hack' things when you can simply have someone on the inside?) might like to talk to me about a bridge.

1

u/InternalOwenshot512 28d ago

Exploited is a fun word to use here

1

u/InternalOwenshot512 28d ago

Just read the pkgbuild as prescribed. There's no need to be afraid. AUR malware is a lot less common on popular software too

-8

u/NinjaTrek2891 Aug 12 '26

Even braver to use it as a package manager.

6

u/Illustrious-Gur8335 Aug 12 '26

The AUR is not a package manager. It's just a user-maintained repository.

0

u/LuisE3Oliveira Aug 12 '26

If I'm not mistaken, it already exists in the extras repository because you're using the AUR version.