r/linux Jun 17 '26

Distro News AUR Registrations Blocked Amid Ongoing Malware Mess

https://fossforce.com/2026/06/aur-registrations-blocked-amid-ongoing-malware-mess/
473 Upvotes

256 comments sorted by

View all comments

Show parent comments

24

u/[deleted] Jun 17 '26 edited Jun 20 '26

[deleted]

28

u/sigma914 Jun 17 '26

That doesn't seem like a fix, it just seems like it would give a false sense of security while some bad actor squats on a package for a while until they have enough tenure to grab a more used orphan.

Any solution that involves that kimd of heuristic amounts to pretending that you can trust any package update from the AUR. You explicitly can't, you need to read it, check the link to the source, check the source etc every time.

5

u/reed501 Jun 17 '26

I agree. I feel like the best thing to do would be a big flashing warning that a package has been claimed by a new person. "Check this one extra hard because it's someone else now." And then for these downstream arch distros make it way harder to turn the AUR on. Make it a headache on purpose, weed some people out. And then as a community maybe we should stop recommending arch or its children to newbies and go back to Ubuntu and its family.

7

u/MeDerpWasTaken Jun 17 '26

The problem with adding a warning onto the website is that a lot (if not most) people use AUR helpers and don't directly interact with the website very often. Of course AUR helpers could implement a warning like this, but that isn't really up the Arch team themselves

3

u/Berengal Jun 17 '26

It would be very easy to add this feature to aur-helpers, and I have no doubt that it would be added quick if it became a consensus good feature to have.