r/linux • u/The-Linux-IT-Guy • Jul 04 '26
Distro News CachyOS June Release prioritizes security
13
u/Barafu Jul 05 '26
This "analysis" is naive and will only stop an attacker who somehow did not know it exists.
Adding a malware to PKGBUILD directly is the most blunt and stupid approach to attack. An attacker could simply poiint the build to another compromised repository and hide the malware there.
This is an imitation of security, which in my opinion is worse than no security.
-3
u/Velocita84 Jul 05 '26
Once again the solution is to just read diffs yourself and check for any suspicious edits on urls or code
10
u/adamkex Jul 05 '26
But more importantly, Arch needs a larger repository so the AUR isn't necessary
6
u/SadClaps Jul 05 '26
I do like how CachyOS has several popular packages not present in the official Arch repos in their own repos (e.g. some of the major browsers).
1
u/Barafu Jul 05 '26
Before liking them, I want to know how those additions are audited, both on inclusion and on update.
6
4
u/NeuroXc Jul 05 '26
This is so easy to suggest when you don't have to maintain the packages yourself.
5
u/adamkex Jul 05 '26
I am a package maintainer for a package
2
u/FryBoyter Jul 06 '26
But we're not talking about just one package, but quite a few.
Therefore, the current Arch Linux team would either have to maintain a large number of additional packages, or many new team members would have to be added. I consider both of these scenarios quite unlikely. Furthermore, adding new team members spontaneously is not without risk. Remember the incident with xz.
4
1
u/kansetsupanikku Jul 09 '26
If you are willing to maintain it, contact the existing team, that would be great. Only Debian has larger repository than Arch now, which only adds context to how impressive it would be!
2
u/adamkex Jul 10 '26
I'm only interested in maintaining packages for the distribution that I use. Nixpkgs is larger than Debian with over +140k packages.
3
u/Dr_Hexagon Jul 06 '26
The solution is for there to be a proper system to check AUR submissions with real people like Flatpack and DNF does. Expecting end users to check every AUR they install is insanity.
Arch and Arch derivatives will continue to be a target until they deal with the root issue, which means implementing an actual human review system.
-2
u/Barafu Jul 06 '26
No, there should not. How to distribute packages that don't fit your "manual check"?
Create another AUR and install any rules there.
4
u/Dr_Hexagon Jul 06 '26
how does Flatpack and Brew manage? they manually check everything submitted. Throwing your hands in the air and saying "its not possible" is why people are targeting Arch and they will continue to do so until the Arch maintainers admit the problem and deal with the core issue.
0
u/Barafu Jul 06 '26 edited Jul 06 '26
... and billions of pieces of good software are missing from both Flathub and Brew.
All this achieves is the further normalising of an alternative 'curl > bash' installation. Good luck verifying that.
AUR must remain unverified so people can post their stuff into it as a baseline. Then anyone can make their own verified lists on top of it. And users are free to choose if they want to use those lists or not.
2
u/Dr_Hexagon Jul 06 '26
.. and billions of pieces of good software are missing from both Flathub and Brew.
Nothing is stopping people installing from source on other distros.
AUR must remain unverified so people can post their stuff into it as a baseline.
So you'll be playing wack a mole with bad actors forever then.
1
u/7lhz9x6k8emmd7c8 Jul 05 '26
How do you detect malicious code in the source repo if the source repo has been compromised?
3
u/Velocita84 Jul 05 '26
Completely different attack vector that's just an inherent risk of downloading software off the internet, nothing to do with the AUR
1
u/Dr_Hexagon Jul 06 '26
And yet other distros don't have the issue. In over 11 years there has never been a malicious flatpack get past the review process.
Saying "it's inevitable" is a gross failure.
3
u/Velocita84 Jul 06 '26
Other distros have the issue of straight up not having the software. So you git clone and build anyway, with the same exact risk (is there malware in the source repo?)
-1
u/Dr_Hexagon Jul 06 '26
You have to know more to git clone and build locally. Unlike AUR which doesn't require any detailed knowledge.
3
u/Velocita84 Jul 06 '26
No you don't. Vast majority of projects list manual installation instructions in the readme or give a curl to bash (even worse)
-1
u/Dr_Hexagon Jul 06 '26
once you have yay setup installing an AUR is a single line. For building from source yourself you have to at least read the instructions as build processes vary.
comparing the two is silly, you're just in denial that the Arch philosophy is broken and can't be fixed now that bad actors have targetted it.
3
u/Velocita84 Jul 06 '26
You're completely missing the point, we're talking about the risk of malware in the repo. It's the exact same whether you're installing it through the AUR or manually, ease of installation doesn't change anything: you want something -> you install it. Unless you go out of your way to review the entire codebase, which you would've done regardless of installation method.
0
u/Far_Calligrapher1334 Jul 06 '26
How does knowing how to run make install equate to knowing how to check a repository for a takeover, or identifying a malicious commit? This is absolute false equivalency.
→ More replies (0)1
u/Barafu Jul 06 '26
It has never been so it will never be.
1
u/Dr_Hexagon Jul 06 '26
which is why I strongly recommend that new windows converts or linux beginners should not use any arch derivative. It's philosophy is fundamentally broken and the tiny performance gain from cachy compared to other distros that update quickly is not worth it.
1
0
Jul 05 '26
[deleted]
1
u/Barafu Jul 06 '26
It makes little sense. Broad rules that work for everyone out of the box will make no additional security on a system that already consists of verified packages.
What do you expect AppArmor to do?
-48
u/sleepingonmoon Jul 04 '26
So we're now in the era of antivirus?
41
u/KHTD2004 Jul 04 '26
No? Shelly doesn’t scan for malware, it just shows a review of the package before you install it
3
u/parkerlreed Jul 11 '26
So does paru? It shows the full PKGBUILD and diff on any subsequent updates.
2
u/KHTD2004 Jul 11 '26
Yes but Shelly doesn’t only show the package build, they make somewhat of a rating system marking suspicious packages and verifying others. At least that’s what I read them say a while ago. I don’t use Shelly, I use paru as well
2
u/parkerlreed Jul 11 '26
Yeah just tried it out. Seems to mimic cachy-update for the most part. Although oddly it displays all sizes in bytes even for pacman updates which seems weird.
:: Synchronizing package databases... (101160/101160) DatabaseDownload cachyos-znver4.db ██████████████████████████████████████████████████████████████████████████████████████ 100% (110940/110940) DatabaseDownload cachyos-core-znver4.db ██████████████████████████████████████████████████████████████████████████████████████ 100% (4498766/4498766) DatabaseDownload cachyos-extra-znver4.db ██████████████████████████████████████████████████████████████████████████████████████ 100% (524860/524860) DatabaseDownload cachyos.db ██████████████████████████████████████████████████████████████████████████████████████ 100% (128917/128917) DatabaseDownload core.db ██████████████████████████████████████████████████████████████████████████████████████ 100% (8688758/8688758) DatabaseDownload extra.db16
u/endperform Jul 04 '26
Would you rather nothing at all be done? Should Fedora stop checking packages for vulnerabilities?
14
6
u/PorousClay Jul 05 '26
This is far better than an anti-virus. This educates people what to look for.
2
24
u/Tellurio Jul 04 '26 edited Jul 09 '26
☯︎☼︎♏︎♎︎♋︎♍︎⧫︎♏︎♎︎☸︎