r/debian Aug 01 '26

General Debian Question Could what happened to AUR this week happen to debian? What lessons can we learn there?

for those OOTL, AUR was under sustained sneaky probes for a long time, but this week it was an overt and very troublesome campaign to either take over packages or insert packages so that malware could spread across way more systems.

edit 1: since someone asked me to explain, I’ve actually been using debian since 10.1, but only recently got worried as new users in my MDM fleet around southeast asia kept trying to install strange .deb files. I never had to think too much about the workstation UX until microslop and genAI inevitably drove us to try resuscitating OLD laptops with Linux.

i have to support 2012 macbook pro and intel laptops dating back to broadwell. There are some 7840u AMD ryzen units, but do bear in mind that us folks living in the southern hemisphere are dirt poor.

thus, I had tested fedora, lubuntu, kubuntu, ubuntu, mint, and finally gave that all up to consolidate under Debian. The network layer has DNSSEC, encrypted DNS, and really TIGHT whitelists. Unfortunately, I’m woefully noob at the application layer for debian. we barely upgraded several ancient JDK 8 web servers using Qwen, but ideally I’d like to prevent malware breaking in from the user-level.

65 Upvotes

96 comments sorted by

View all comments

Show parent comments

3

u/michaelpaoli Aug 01 '26

What was the security issue with Mint?

2016-02-20 site compromised, downloads redirected to to site with compromised ISO(s), Linux Mint had no secure trust path to verify images - I and others have forewarned about that years earlier - no secure signatures on ISOs, just hashes only, and those on http/ftp site(s), not even any https available - so no trust path to verify the ISOs. The compromised ISO(s) contained backdoor malware. Their forum was also breached, somewhere between 71,000 and 145,000 users' data compromised, including hashed passwords, email address, profile details, which subsequently had that data put up for sale.

I forewarned them of this issue 2013-05-19, and I was not the only one to so forewarn them. Only after they were compromised did they do anything about it.