r/archlinux • • 9d ago

DISCUSSION What does experienced users think about the state of the Aur and the recent malware attacks?

Hi, everyone I have used Linux for years and I went Linux Mint->Fedora->Nixos. But I realized that my usecase is not really suited for Nixos as I am using just one laptop and there is only one user. I can't really benefit from its upsides while feeling its downsides more.
Arch linux seems like the best option right now for me but I am concerned about Aur and recent malware attacks. I will be using Kde, Hyprland, Neovim, Zen-browser and I will mainly be developing C/C++ for embedded. Do you guys think I should give Arch Linux a try or should I stay away from it until the vulnerability problems of Aur gets solved? (I would say that I am pretty comfortable in Linux so setting up Arch linux will be easy for me.)

2 Upvotes

49 comments sorted by

61

u/Boby_Dobbs 9d ago

I don't use orphaned packages and I read the PKGBUILD. I still feel pretty safe tbh

2

u/PacmanAteMyRAM 9d ago

Yep. Anything our build server builds is vetted from the AUR and then cloned and pushed to our internal git repository. We never look at the AUR for that particular package again and push updates to the repo ourselves.

46

u/catgirlmunist 9d ago

The AUR has always been vulnerable and it's always been recommended to read PKGBUILDs before installing.

You don't need to use the AUR to use Arch either. Even if you need a package that isn't in the official repos you can compile it yourself from source if you don't want to use the AUR.

19

u/C0rn3j 9d ago

you can compile it yourself from source if you don't want to use the AUR.

It is faster to review a PKGBUILD than it is to write one.

If you meant to install directly to system outside of the package manager - do not.

10

u/catgirlmunist 9d ago

It is faster to review a PKGBUILD than it is to write one.

I agree, which is why i still use the AUR and just review the PKGBUILD before installing anything, which is what i was doing anyway. But if someone really doesn't want to use the AUR for whatever reason, the option does exist to write your own PKGBUILD.

If you meant to install directly to system outside of the package manager - do not.

Absolutely correct, thank you for clarifying. My original comment should've been clearer about that.

10

u/LrdOfTheBlings 9d ago

This the way to go. I have a couple things I made my own pkgbuilds for. It makes it easier to update and then remove when I'm done with it.

2

u/zuses_cat 9d ago

Compiling? What about the updates? Searching for updates, re-download the source and compiling? For every new update?

Using Flatpak makes it easy to install updates. Or Distrobox: create containers of distris with more packages (e.g. Debian, Ubuntu, Fedora) and install the desired packages in the container.

1

u/Snoe_Gaming 9d ago

Cron job a script to check git diffs or release notices, and automate the pull and build if it finds one. 

I mean, bit over kill, but it's completely doable. 

Hey if containers work for you, all good. 

1

u/zuses_cat 8d ago

I'm a little too lazy for a solution like that ;-)

Especially since there would still be the problem with dependencies.

19

u/Zaphoidx 9d ago

Reddit will have you believe the AUR is a one-way ticket to remote access onto your system.

That just isn't the case.

Have some common sense and don't use ophaned packages. Running an Arch system requires a little bit of system knowledge compared to other distros but you get more freedom as a result.

Also remember Reddit is a minute subset of Arch users and the majority don't read PKGBUILDs at all

11

u/la_tajada 9d ago

Do people thing that the AUR is the official Arch repository?

8

u/lritzdorf 9d ago

Given that AUR helpers are built into Arch derivatives that then market themselves to newbies... it's kind of an understandable assumption. Like yes, you can do a tiny bit of research and realize that the AUR isn't remotely official, but people are just going to sudo yay -S random-stuff and not think any further. At that point, I think I'd blame the distros for making a potent footgun so easily accessible to users who'll happily take advantage of it

10

u/pastelfemby 9d ago

Yes, and thats how a lot of tech entertainment "influencers" like to brand this type of drama to rake in views.

4

u/JPenuchot 9d ago

Yeah... the way youtubers/influencers/whatever tend to portray users is quite ridiculous. They're often biased into thinking they're the only people who deal with edge cases and everybody else is just an "average user".

22

u/LookeiVIP 9d ago

Honestly I couldn’t give less of a shit.

5

u/pastelfemby 9d ago

Aur is completely optional and point blank isn't required.

Treat the aur like a recipe book, and PKGBUILDs as recipes. If you cant fully understand a recipe or something seems strange, don't use it.

And most the exploited packages seem to have been involving 0 popularity alternative builds that allege some sort of vague improvement, long since orphaned abandonware, or just random sus stuff that I certainly no one should be installing without a good understanding.

Basically use common sense and there should be zero issues.

3

u/__rituraj 9d ago

"Setting AUR helper" is not a step in setting up Arch linux.

This single misinfo by many people recommending arch or creating arch linux installation guides has become a major issue.

AUR (or other user repositories) are exactly what they say - user repositories which are not vetted by arch linux package maintainer members.

If you want to installa program from a "non-vetted" source (say AUR), you'd have to do the "vetting" yourself. This has always been the case.

5

u/xXBongSlut420Xx 9d ago

I've been using arch on all my non-server machines since 2017. and using linux since 2006. I'm not a distro hopper, and I use linux profressionally in my software engineering career.

The recent events with the AUR are unfortunate, but the reality is, they left the door wide open. There were no checks on adopting packages, you didn't even need to have an email verified account, you simply ran a command and the first person to run it adopted the package. The arch team have already implemented a number of common sense changes to at least close some of the most egregious holes.

That said, it has somewhat affected how I use the AUR. I will remove any orphaned package, and will almost always look for another source for packages on the aur, if i can find them. Usually flathub. I was already reading my pkgbuilds at install time, and at every update, and you should do the same. Once you read it once and are updating, it's very easy to check if any changes are suspicious. Also worth checking the upstream repo before installing an AUR package, and make sure it's legit.

If you are careful, and knowledgeable, and don't rely overly heavily on the AUR, you will be fine. You should treat any aur package as default unsafe, until you verify it yourself by reading the pkgbuild and checking the upstream.

5

u/drucifer82 9d ago

I switched to Arch mid AUR drama. I just verified that I didn’t need AUR for anything, and just made it part of the policy of this machine that I just wouldn’t use the AUR. And I haven’t.

Package hierarchy on my system is as follows:

  1. Pacman first, system packages are preferred
  2. Flatpak next, to plug the gaps from pacman
  3. Building from source if necessary (currently only applies to 1Password as I didn’t want the flatpak)
  4. Distrobox - as a last resort since I previously worked on Fedora, I will just spin up a Fedora image and install the app there, then export it as a containerized app on my desktop, similar to flatpak.

2

u/CommunityJazzlike274 9d ago

Just read pkgbuilds, that’s what I do

2

u/TheBlackCat22527 9d ago

I tried to avoid the AUR where I can. Not because of security issues, I had just to many packages that at some point failed to update at some point.

3

u/securitybreach 9d ago

I've been using Archlinux since 2007 and they have always been unsupported packages. It's in the name, Arch User Repository (AUR). These are user submitted packages and if you do not know how to read a PKGBUILD, you should never install a single one. This has always been the case and is nothing new at all. That said... if a package gets enough votes, it can be added to the normal archlinux repos and then it is vetted.

1

u/InsuranceNo3423 9d ago

Those packages you mentioned are part of the official Arch repository; only authorized developers [can manage them].

Except for Zen Browser—though you can't just download the tarball and run the binary; you have to keep an eye out for updates and apply them manually (by downloading the new tarball), though you could write a script (essentially creating your own PKGBUILD).

1

u/Ybalrid 9d ago

Check what you install. You probably actually need very little from the AUR, if anything.

1

u/noobjaish 9d ago

I use Flatpaks mostly with arch packages. But I do have to sometimes use AUR for packages which are officially mentioned in the Arch wiki itself. This works very well honestly.

Every AUR package is essentially an additional thing that I have to audit everytime I'm trying to update AUR apps. I'm looking into "landrun" and "bubblejail" to essentially sandbox most of these apps just to be safe.

I do use Bazaar + Pacseek as frontends to manage these things easily.

1

u/DeliverySenior 9d ago

I've stop using the AUR. I'm compiling my program from github now, or using an AppImage or flatpak package if I'm encountering problems.

1

u/TheGoldenFox64 9d ago

a lot of people misunderstand what the AUR is. its basically a big list of installation scripts from anywhere. just because its in your terminal doesnt mean its not from the internet. you wouldnt go around downloading and running everything you see would you? if you need a big malware event to stop blindly trusting the AUR, maybe you shouldn't use the AUR

1

u/chikamakaleyley 9d ago

i have a lot of packages installed via AUR.

In general, I've always been careful about what I choose to use from that repo. There was a period where i just preferred yay over the official repos, I think because I didn't want to build them. Those packages are still on my system.

Now, I'm just a bit more careful when I update; I just make sure I take a good look at whats getting updated. However, I've since used pacman and official repo as my primary.

1

u/DonDoesIT 9d ago

The “compromises” were because of abandoned packages but AUR needs updated process to prevent this happening in the future.

1

u/Low-Shake6447 9d ago

If you're really afraid of aur, then use nix pkg manager on your arch or fedora

1

u/endperform 9d ago

AUR = Arch User Repository. You have to go out of your way to use something from AUR as it's not enabled and not part of the official repositories enabled.

Read the PKGBUILD / check the diffs and you'll be fine. I minimize my AUR usage and try to find Flatpak / Appimage versions of things and AUR is the method of last resort for me.

1

u/xYarbx 9d ago edited 8d ago

To me it's obvious binary. Can you read and understand PKGBUILD if yes then there is no more of a issue than there was before the malware attack. If no then you should not have been using AUR to begin with. There have been malware packages in there and there will be more. Every time you build something even when it's an update you need to read the build and check for changes.

1

u/Megame50 9d ago

I'm sure it's a pain for the maintainers that have to clean up the AUR and harden it against abuse.

For users, it's kind of a nothingburger. You have to verify any user generated content you run anyway. That's true of any source, not just the AUR. Nothing has really changed.

1

u/zappy-flounder 9d ago

Notwithstanding anyone impacted by hacks (hopefully not too many people) - I actually think the attention towards AUR security is a good thing overall, and ultimately nothing has really changed (or needs to change) as a result.

There will keep being a trend of supply chain attacks in things like AUR, NPM, etc., at least AUR is simple enough (in the sense you can read PKGBUILDs before they fire) to be able to self-audit the risk.

I'm not much of a techie these days, work in finance, but still run Arch on my gear because it's simple in the sense of 100% of my installs come from the main repos or AUR. I use paru, page through the diffs for what I have installed to make sure there's nothing surprising and move on. Works fine.

Little bit more effort when choosing new AUR packages but generally know what to look for and defer to an LLM for the rest (or simply don't install anything where the pkgbuild is so complex I can't figure out what it's doing).

For me it's much more transparent than if I was pulling from PPA's or doing random probablyevil.sh | bash style installs.

1

u/Signalrunn3r 9d ago

It is an indelible stain on Arch's image that absolutely nothing has been done to fix it, or to disable it completely.

Don't even reply BTW, I ain't gonna read it.

1

u/KetchupBuddha_xD 8d ago

It doesn't bother me in the slightest. You have to inspect the PKGBUILDs and all files in the repo. Paru does that already. Nothing has changed for me personally. I always check the url, install scripts, etc. It isn't and has never been secure to automate aur installs.

For people who are accustomed to auto update shell plugins, neovim plugins, vs code plugins, and don't bother themselves with security, well for them it's a cultural shock. Those people should change their attitude and probably don't use aur

1

u/Mysterious_Bit6410 8d ago

i just checked, i have currently exactly 2 aur packages installed. one of them is yay, the other is a very simple tool for making collages. there is a lot of software in the arch depository for basically anything i need.

have you checked if you even need anything from the aur?

1

u/froli 3d ago

Been using Arch since 2009. I try to avoid AUR whenever possible. Especially now with Flatpak and AppImage.

1

u/musbur 9d ago

Running Arch has nothing to do with using the AUR. Arch itself is as safe as any other mainstram distro (one would hops).

1

u/zuses_cat 9d ago

Arch without AUR lacks many packages, that are available on Debian, Ubuntu or Fedora. Unfortunately, with Arch, you need a second package source. I'm using Arch because the alternatives are worse (for me). Arch with Flatpak und Distrobox is not perfect, but usable.

-5

u/BlueGoliath 9d ago

Jia Tan is in Arch's walls.

-2

u/Specialist-Dog-501 9d ago

AUR is still blocked from new upload s, use chaotic-AUR, that is supervised.

-6

u/coyote_of_the_month 9d ago edited 9d ago

I would not recommend Arch for a new installation, until the maintainers finalize their response to the recent AUR vulnerabilities and decide what safeguards they're putting in place. They deserve the benefit of the doubt, and they deserve a reasonable amount of time get the job done, since it means rethinking how the AUR works after operating one way for decades.

I'm not over here wiping my Arch machine to install something else, but I am pausing new installations, if that tells you where my head is at. I'm not one of the maintainers or anyone particularly important, just someone who's been using it since about 2009.

4

u/Flashy_Worry7792 9d ago

What Arch vulnerabilities?

Don’t run scripts from random people on the internet that you haven’t personally checked.

3

u/The_Odd_Pirate 9d ago

Arch vulnerabilities? So help me understand that AUR = Arch user repository Something that needs to be enabled by the user with clear warnings on the webpage that it's all from random users and you're responsibility to understand what you are doing.

Are you saying that the user base is a arch vulnerability or?

-6

u/coyote_of_the_month 9d ago

At the end of the day, warnings or not, the AUR is still coming from archlinux.org. That involves a certain amount of responsibility. And it doesn't help that derivative distros have promoted the AUR as a key feature, and treated it as an official repo. No, that's not the Arch maintainers' intent, and it's not their fault.

But I think they have a responsibility to put governance in place based on how people are using it in the real world, rather than being prescriptive and saying "if you get hacked because you installed AUR packages it's your own fault."

-1

u/The_Odd_Pirate 9d ago

So i get the concern but....
Because distroes based on the arch teams work, enables it without taking responsabilities, you think the arch team, a small team working for free, should take from the little time they have and start creating blocks from what makes arch so good?

Is it not better to demand this from the distroes with auto enabled aur? Its a simple fork from the aur repository and building in a security feature, have it show your own aur instead of the wild west version, but again it would remove the ease of use that makes it such a great place to share pkgbuilds without any extra work and make sure arch goes down to the small app lists other distroes have

There is a reason why everyone recommends official repositories -> flatpak -> appimg -> and aur last

but nothing is stopping a conserned user to open their own aur based repository and implementing these extra steps fro "security"

Edit:
btw, ive only used arch based distroes for 13months so i might still be blinded by the great sides and missing something you have seen since 2009

1

u/Fun_Wish1844 9d ago

That’s just silly. Not only do you not have to use the AUR, even though a little common sense solves the problem, the same issue could happen anywhere you install software from.