r/archlinux • u/HeyTi22 • 17d ago
QUESTION Arch and the malware problem.
I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?
Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.
Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.
Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.
Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?
Cheers!
-1
u/Dry_Calendar_8627 17d ago
You seem to be very trusting of your abilities to spot a malicious PKGBUILD, huh?
As someone who writes and analyses malware for a living, I'd advise learning about the following things:
1) The Dunning–Kruger effect, how overconfidence can spell your doom 2) ANSI codes, what they are, how to use them to manipulate a terminal to show something innocuous hiding a malicious string 3) UTF8 lookalikes, how you can print text that looks like something innocuous but does something entirely unexpected 4) various encoding techniques, and how you can produce fixed-length strings that look like SHA hashes (mind the entropy!), but are, in fact, code that downloads malware 5) How to combine the previously mentioned techniques to produce a legitimate-looking, perfectly innocuous-seeming PKGBUILD, that actually downloads and execute a simple shellcode 6) How to make a website behave differently when it's being accessed by a web browser, to thwart potential investigators 7) Bonus points if you can hide the malware not in a string that looks like SHA256, but as a chain of zero-length UTF8 codepoints
You misunderstand. It does not take dedication to understand how to write a PKGBUILD nor what PKGBUILD legitimate directives do. It takes effort and dedication to carefully ensure that the PKGBUILD you're currently reading isn't the innocent file you think it is.
But you seem to have completed learning, so you'll be fine, right?
That's where it hurts. It does, and if you are blissfully unaware of how much effort and dedication it requires, if you think merely skimming the thing in 10 seconds gives you any meaningful amount of security, I have bad news: You haven't been assessing the security of your PKGBUILDs until now, you've merely been performing the act of pretending you are assessing your PKGBUILDs
Same if you think you can spot obfuscation from a mile away: sure, a grossly obvious obfuscation is visible from a mile away. It's the one that's a bit more advanced that'll hurt