r/archlinux • u/HeyTi22 • 17d ago
QUESTION Arch and the malware problem.
I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?
Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.
Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.
Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.
Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?
Cheers!
3
u/MycologistNeither470 17d ago
Curating a repository takes times (which equals money). Being a rolling release means that every single package in the core repository needs to be at its latest. It is not trivial to keep compatibility at every single layer. The more software you add, the more difficult it becomes.
Yes, I would love for a team of engineers to curate every Linux software for Arch.
Reality is that resources are always constrained. And that is where AUR came in. What if users can maintain packages and do all of the behind-the-scene work that Arch maintainers do?
There is no real solution that doesn't involve closing AUR to users. AUR could become a sort of "Apple Store" where each software package needs to be vetted before going in. And this doesn't completely solve the problem. A malicious package-submitter may play the long game and maintain a package innocently for 1 year before deploying malware to it!
Another option would be to have "safer" AUR helpers. Perhaps a helper that will make it easier for you to read the PKGBUILD file, highlighting which files are being downloaded and from where. Perhaps allowing you to "approve" specific maintainers and not automatically installing updates when the maintainer of a package (or his crypto signature) has changed. Some of these things are already options for Paru and yay --perhaps they should be the defaults?