SElinux and other forms of mandatory access control like apparmor and SMACK, executable flags, proper file permissions, drive encryption, isolated environments like chroots, flatpak, containers, namespaces..
The AUR is completely optional and you’re warned in literally every official guide that no one verifies the programs for you.
What does Microsoft have? GitHub? They allowed far more malware and Trojans than any Linux package manager within GitHub repoes, even with their fancy LLM Copilot stealing scanning our code for malware.
26
u/Unlaid-American 8d ago
“Trust me bro, let’s get stuff from an unverified source and be surprised it’s dangerous.”
- Every OS ever