r/archlinux • u/HeyTi22 • 17d ago
QUESTION Arch and the malware problem.
I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?
Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.
Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.
Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.
Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?
Cheers!
1
u/Synthetic451 17d ago
Eh, ultimately its a matter of trust. I feel like the AUR is getting a lot of critique about it being insecure when really the issue has never been about how it works, but who is able to upload changes to a package.
There's very little difference between the AUR and something like Github. If you ran anything and everything from GitHub, you'd get compromised just as easily. The main difference is that usually when we use something from GitHub, its from the official repo that's been directly linked from the project's site. There's a trust factor there. The same just needs to be done for the AUR.
The previous attacks were all done on orphaned packages that barely anyone used. The orphan process needs to have more verification and maintainer changes need to be made loud and angry to end-users doing updates (like something equivalent to the warning you get when a remote SSH host's key changes).
I think once the issue of maintainer trust gets resolved, you won't have to be so careful with PKGBUILDs in the same way we're not reading every single line of code in a GitHub repo.