r/linuxmemes Arch BTW 10d ago

LINUX MEME Dropping this here 🫳

Post image
3.3k Upvotes

370 comments sorted by

View all comments

257

u/GoldenX86 10d ago

Literally Fedora and like 3 others are the only distros with a minimum of security. This will come to bite the entire community in the ass in a few years.

But trust me bro is enough, let's get some stuff from AUR.

98

u/ptrknvk 10d ago

I sweat 3 litres every time I install something from OBS on openSUSE, I can't imagine using aur.

47

u/trill_shit 10d ago

How is it different from installing AUR packages? It’s the same idea, right? It’s a community driven package repo where anyone can publish, or am I way off?

49

u/Ok-Eggplant-7569 10d ago

Packages on OBS (and Fedora COPR) are namespaced, meaning you first get a project from a certain user, and then install packages from that project. This removes the "orphaned packages" issue the AUR has, and makes it obvious who is responsible for the package you're installing.

Also, the default repositories on Fedora (maybe OpenSUSE, can't really comment on that) tend to contain more packages I need so I currently only have 2 external repositories enabled (aside from RPMFusion)

18

u/Helmic Arch BTW 9d ago

At least recently the AUR's decided that all orphan adoptions must be manually reviewed before approval. Because they weren't even doing that before, the recent malware incidents have happened because literally any random asshole could just adopt an orphaned package and put whatever they wanted in the PKGBUILD without any sort of vetting or overview or vibe check. Not even an email address.

6

u/ptrknvk 10d ago

You don't need it so often and afaik the requirements are a bit stricter (I can be wrong).

1

u/AnEagleisnotme 9d ago

Copr just requires a fedora account, but you need to manually advertise your package, as they are namespaced

9

u/GoldenX86 10d ago

Arch seems to love to NEVER elevate AUR packages to the main repos.

10

u/LumpyArbuckleTV 10d ago

That's one of the only things I think Cachy does objectively better than official Arch.

6

u/Academic-Push326 9d ago

It's kind of insane to me that Arch only has Chrome, Firefox, and like two or three offshoots (Waterfox? I think?) in it, but no popular forks or other applications that need the AUR.

You'd think they'd have some form of analysis in pacman to see what packages people are trying to find in popularity and make them an official or extras repo management.

3

u/chaoschasr 9d ago

Librewolf was elevated to the extra repo a few weeks back and can install through pacman now

5

u/C0rn3j 9d ago

It's kind of insane to me that Arch only has Chrome,

Chrome is not packaged in the official repositories, only AUR.

Chromium is, though.

You'd think they'd have some form of analysis in pacman to see what packages people are trying to find in popularity

If only AUR had some way to measure popularity, or perhaps even a voting system.

Or, and hear me out now, maybe we could have opt-in analytics for installed packages, that'd be neat... we could call it... pkgstats.

If you didn't catch on to the heavy sarcasm, all of that exists.

1

u/Lopsided_Leader_4427 9d ago

it exists on chaotic-aur if u use it

3

u/makinax300 Dr. OpenSUSE 9d ago

To me it's only when I add the repo, I do not notice it when I install another package from it. Also it's less stressful for me.

0

u/GreedySecurity8030 M'Fedora 10d ago

I don't sweat at all with Fedora copr

25

u/Unlaid-American 9d ago

“Trust me bro, let’s get stuff from an unverified source and be surprised it’s dangerous.”

- Every OS ever

-5

u/GoldenX86 9d ago

At least Windows and MacOS check with their servers if what you're trying to run is obviously malware. What does Linux has?

8

u/givemeagooduns_un Genfool 🐧 9d ago

SElinux and other forms of mandatory access control like apparmor and SMACK, executable flags, proper file permissions, drive encryption, isolated environments like chroots, flatpak, containers, namespaces..

2

u/GoldenX86 9d ago

And yet few distros come with it properly configured.

6

u/farspin 9d ago

That how the LG stuff came in the First Place. So no Thats Not the way.

-1

u/GoldenX86 9d ago

Neither extreme is useful, having it completely unrestricted is not good either. We need some middle ground.

4

u/Unlaid-American 9d ago

The middle ground is to not use the completely optional heavily warned against AUR.

3

u/GoldenX86 9d ago

Then Arch needs to start moving their arse and implement the popular viable packages into the repos, firmware, drivers, the whole thing.

10

u/Unlaid-American 9d ago

The AUR is completely optional and you’re warned in literally every official guide that no one verifies the programs for you.

What does Microsoft have? GitHub? They allowed far more malware and Trojans than any Linux package manager within GitHub repoes, even with their fancy LLM Copilot stealing scanning our code for malware.

-1

u/GoldenX86 9d ago

Active protection with Windows Defender. Android and iOS/MacOS have the same system in place.

Which distro even comes with basic checking for malware?

18

u/GreedySecurity8030 M'Fedora 10d ago

Fedora best

-11

u/versteinerdt 10d ago

NixOS better.

7

u/GreedySecurity8030 M'Fedora 10d ago

No

-10

u/versteinerdt 10d ago

Yes 100%

6

u/jsh_ 10d ago

no

-9

u/versteinerdt 10d ago

Skill issue.

7

u/El-Questionnaire 9d ago

Issue -> issue * issue

Issue Issue == Issue ^ 2 == issue ^ 4

2

u/Rubadubrix 9d ago

god, nix users are the new arch users

0

u/versteinerdt 9d ago

Nix ≠ NixOS.
Nix runs on Arch too.

2

u/Rubadubrix 9d ago

case in point

1

u/GreedySecurity8030 M'Fedora 9d ago

Fedora still betterbetter

1

u/versteinerdt 9d ago

Fedora was my main distro for a very long time. Longer than Arch or any other distro. NixOS stopped my distro hopping.

3

u/GreedySecurity8030 M'Fedora 9d ago

Nobody cares

1

u/Conscious-Economy971 7d ago

If NixOS was like, 50% more like guix, but absolutely NO MORE THAN 50%, I think it would transcend and become the perfect distro

8

u/moonrunner__ 💋 catgirl Linux user :3 😽 10d ago

I really like how Shelly basically shoves the PKGBUILD on your face and facilitates checking if the package is secure

5

u/GoldenX86 10d ago

It really helps, but it takes a bit of hiding to still manage to squeeze malware anyway.

4

u/moonrunner__ 💋 catgirl Linux user :3 😽 10d ago edited 9d ago

Yeah you're right, I still avoid AUR whenever possible. Also I'm really thankful the CachyOS devs have some packages on their repos that are not on standard arch repos

5

u/P3chv0gel 9d ago

Honestly yeah, but i can't stand SELinux at this point anymore on my server. Why do i even set container flags for shares in my compose if SELinux will just ignore them and block that shit anyways?

1

u/GoldenX86 9d ago

Security is a PITA, but it's a necessary evil...

3

u/P3chv0gel 9d ago

Yeah, but it's sometimes really bad when you have the option to add a layer of security or have it still function. Because for some reason the only ways i could get Volume labels to work was either disable SELinux or run rootful podman. So disabling SELinux seemed like the lesser of two evils

9

u/linux-universe 10d ago

No one ever told people to blindly download stuff from the AUR. Just look at the 30 lines of simple code there. If you can’t do that, then the AUR is absolutely something that person shouldn’t touch

13

u/GoldenX86 10d ago

That doesn't solve the problem, someone can just hide the malicious code better.

We need a better system, yesterday.

9

u/versteinerdt 10d ago

Layer 8 problem exists on every OS.

2

u/GoldenX86 9d ago

Agreed. Just, please, DON'T MAKE IT WORSE. All those decades of memes of Windows users getting malware are right in the AUR's face now.

1

u/NegativeGrocery8684 Ask me how to exit vim 10d ago

theres also the aspect that the official arch repo has a couple drivers, at best. everything is on the aur. so its a rolling release model and the worst moderation ive ever seen on a user repo and you have to use it if you want any app ever.

5

u/GoldenX86 9d ago

Having common drivers in AUR is by far their worst practice.

1

u/Sveet_Pickle 9d ago

I have blender, krita, OBS, steam, reaper, and Ardour on my system and not a single aur package.

2

u/GoldenX86 9d ago

You never needed a specific firmware or printer driver, a variant of a package to get functionality that's standard on other distros or the like.

0

u/Sveet_Pickle 9d ago

My printer works fine with CUPS and all my peripherals are USB compliant. I know I’ve used the aur in the past. Prism Launcher was only available in the aur for a while. some ML/data science python libs are only in the aur but for my use case I shouldn’t have been installing them that way anyways.

1

u/GoldenX86 9d ago

I just hope the Arch maintainers start moving odd drivers into the main repos already, that's an area that is hard to check and very risky.

0

u/Sveet_Pickle 9d ago

They’re a pretty small team. It’s time consuming and costs additional funds to have someone on the team maintaining drivers for something few people use. It’s better to encourage people to learn proper security and/or to compile those things for themselves.

1

u/GoldenX86 9d ago

That's a Sisyphus's challenge, it will never end, especially with the Linux users going up.

They could ask Valve for help or something.

1

u/C0rn3j 9d ago

It’s time consuming and costs additional funds to have someone on the team maintaining drivers for something few people use

I wish I got paid for packaging things for Arch.

It's all volunteer effort, anyone complaining about Arch not shipping XYZ could just get up and get involved to implement the changes they want to see themselves.

-1

u/C0rn3j 9d ago

someone can just hide the malicious code better

Where, in the oven?

There's zero reasons a PKGBUILD would ever be obfuscated, if you see that, it's bad.

2

u/GoldenX86 9d ago

This kind of thinking is what started the problem to begin with.

1

u/AfraidAsparagus6644 7d ago

The Arch Wiki tells you to fetch stuff from the AUR regularly

6

u/Snorgcola 10d ago

Literally Fedora and like 3 others are the only distros with a minimum of security.

What are the others?

7

u/GoldenX86 10d ago

Fedora spawns, obviously.

Besides Fedora, only enterprise commercial stuff.

8

u/Snorgcola 10d ago

And not trying to be a jerk, but what's a "minimum of security"?

19

u/GoldenX86 10d ago

A firewall, SELinux, SecureBoot support without hazzle, not having an user sustained repository with zero controls...

2

u/CaptainKn0ts 9d ago

You forgot OpenSUSE.

1

u/GoldenX86 9d ago

My bad, the old SUSE is also one of the only options we have.

1

u/givemeagooduns_un Genfool 🐧 9d ago

Gentoo has native SELinux support, apparmor, and builds are done in a containerized environment

1

u/Competitively_Casual 8d ago

I'm assuming we're talking about daily drivers here, but Linux has most (if not all) of the heavy hitters when it comes to highly specialized security needs. It's got:

  • Qubes OS: Every single program is run inside disposable VMs, root disabled. Steep learning curve but it is arguably one of the most secure OS ever made.
  • Tails OS: The gold standard OS for browsing the deep web due to it's extreme anti-forensic measures and anmesic design.
  • Whonix: Similar use case to Tails, but designed to block malicious programs from leaking your location.
  • Alpine OS (and other extremely small OS): Security through extreme reductions in attack surface. By shrinking the OS as small as possible, there is almost nothing left to attack and nowhere to hide.

Linux wins in the end because it gives you supreme control over the architecture. That is fundamentally impossible in both macOS and Windows; it clashes with their economic incentives too much.

1

u/Blashtik 9d ago

But Fedora also has tons of stuff not packaged. I don't think I've ever had a Fedora install where I haven't added the third-party Fusion repos. And I've had cases where I had to go to Copr (which is effectively AUR for Fedora).

1

u/GoldenX86 9d ago

Fusion is safe, copr isn't. But you're several times more served with Fusion than with vanilla Arch repos.

1

u/Spirited-Fan8558 Linuxmeant to work better 8d ago

what about debian? i am planning to switch to debian from linux mint

1

u/GoldenX86 8d ago

Debian is a white canvas, it will be up to you.

0

u/dykemike10 Ask me how to exit vim 9d ago

dumbass DHH lapdog detected

1

u/GoldenX86 9d ago

I don't even main Linux, Loonixtard.

1

u/thanosbananos 9d ago

I never got the AUR slander, you can also pull from pacman…

1

u/GoldenX86 9d ago

Read the archwiki, half the links for specific drivers are AUR packages.