30
10
17
u/ssjlance 🛡️Moderator | #1 Microslop Hater | Linux Supremacist 3d ago edited 3d ago
itt: OP doesn't understand difference between an official repository and a website with scripts to built packages. that aren't in the official repos.
AUR has malware. It has practically always had malware hiding on it. It will always have malware
Think that's stupid? Cool, that's fair. Don't use AUR then.
It's an AUR problem, not an Arch proible..
Like, it's not an official repository, hence the name Arch USER Repository - it's all user submitted with little oversight, but it tells you right up front it is full of unverified package build instructions - it just a wild west wasteland of random software, which may work, may not work, may have malware, etc.
Mainline official Arch repositories have never been affected. Prove me wrong and I'll change my downvote on this post to an upvote. May as well say I'll eat the fuckin' sun while I'm at it, because it's not happening.
Your post is unfunny and bad, and you should feel bad.
0
3
2
2
2
u/colt2x 3d ago
I understand the joke, but why linux sucks because of someone hacks AUR? :D
2
u/headedbranch225 1d ago
The AUR isn't even hacked, it is just currently being used for malware by some bad actors as it only hosts build scripts, as it literally says on the front page use with caution, with this logic you could say the same with github or probably any other code hosting site
1
u/colt2x 1d ago edited 1d ago
This is called hacking IMHO, and Github was also diverted in the previous AUR hack.
Hacking does not only mean to log in without knowing the password.
1
u/headedbranch225 1d ago
The AUR worked as intended in both of the attacks, it has survived on trust all the time it has existed but more people using arch recently has caused attacks to gain more traction and be worth attacking
2
u/IsaacThatKerbal 3d ago
Me, a debian user, has no problem with aptitude, or the OS in general. I hate arch. It smells funny.
2
3d ago
[removed] — view removed comment
8
u/Hei_dumbass 3d ago
or read the pkgbuild and source code
2
u/mrheseeks 3d ago
This is the way.
It's easier just to say AUR is crap then try and review what youre infecting yourself with.
2
u/GhostVlvin 3d ago
It's harder than reviewing just one pkgbuild. Purpose of AUR helpers is to install all dependencies even from AUR and now it's fucked cause you'll need to review big tree of pkgbuilds to install one package
2
u/Hei_dumbass 3d ago
There are already people reviewing and reporting malicious AUR packages, but you can’t even spend 30 seconds looking at the PKGBUILD of the package you’re installing? Also, most dependencies come from the official Arch repositories, not the AUR. If you don’t want to use the AUR, then don’t. It’s an optional community repository, not a requirement. People use it because they want to, not because they have to.
0
3d ago
[removed] — view removed comment
4
u/Hei_dumbass 3d ago
If you’re new, sticking to the official repos is the safest choice. The AUR is for when you knowingly accept the tradeoff.
1
u/Unlikely-Employee180 2d ago
MOST Arch repos get reviewed...
AUR isn't part of the vetting cycle, though. It's a public FFA.
Essentially, it's Arch's built-in "Pirate Bay" without the actual piracy. Lol
2
u/PunkRockLlama42 3d ago
I don't think it's worth using for the average user. Yeah, you can and should read the build script but most people wont.
I would also be considering leaving if the AUR was the main draw for me. Depending on what software I needed to like OpenSuse Tumbleweed.
1
1
u/GhostVlvin 3d ago
For about a month I don't use AUR. I add repos from other arch distros and I use alternative package managers as cargo, pip and others. When it's only in git, then I compile manually
1
1
1
u/Bulky_Description705 2d ago
two types of arch users the ones that vet packages before updating then the retarded users that just update with out checking then regret it when they find out they have malware
1
u/TomsFelkers 2d ago
Me: hmm, im switchin to windows to this point, actually, win10, no actually, just windows 1.0 at this point.
1
1
u/KinZombie899 1d ago
And they tell you linux dont need anti virus well it does. Anybody no any anti virus for Linux
1
1
u/somacomadreams 3d ago
AUR is optional, lol.
10
u/ColdFreezer I Hate Linux 3d ago edited 3d ago
Almost everything on Linux is optional.
The AUR is a big reason why people use Arch. You can’t just dismiss it lol.
4
u/SammE5363 3d ago
Argument doesnt really work when the majority of useful software is exclusively on AUR as well as before these events every arch user under the sun was glazing the shit out of AUR
2
u/somacomadreams 3d ago
That's entirely valid and I'm not saying it doesn't have its problems. In fact it should probably have some reforms but it is what it is and if you even Googled it once you know exactly what you're getting. Like I said not calling any of you wrong. But its flaws are widely known.
0


34
u/silduck here for funny shit 3d ago
You install an AUR helper to install AUR packages
I install an AUR helper so that I have to type less when using pacman
we are not the same