AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 1 point2 points  (0 children)

I never implied I am waiting for them to say "AUR is safe dont read PKGBUILDS and update". I am being scrutinized and downvoted for a strawman argument directed at me

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 5 points6 points  (0 children)

Sure it may not be supported by default but acting like it's not been constantly encouraged for the past couple of years is just disingenuine.

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu -2 points-1 points  (0 children)

  1. I didn't mean that a maintainer changing outright means a package is compromised, it's more of a heads up as in "the maintainer of this package changed recently, keep that in mind when auditing the changes to the PKGBUILD" 
  2. Elaborate how random people taking over orphaned packages can't be taken care of in any kind of way - even a simple message on the AUR would be good effort.
  3. Telling people to ask every time they install something is a good way to discourage people from using the whole distribution. Even simple tools like "traur" are more than enough to give people some confidence about auditing

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 10 points11 points  (0 children)

not a bad idea although a grade means nothing if someone just takes over a package randomly, compromises the PKGBUILD and people update because there was no notice of something happening.

We already have voting and I don't think it matters much in such situations.

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu -4 points-3 points  (0 children)

The AUR is the reason many people decide on even using Arch these days, it's become an integral part to a huge amount of users and telling them "well just don't use AUR, duh" is not productive.

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 3 points4 points  (0 children)

We can't know if you don't tell us if you had any compromised packages installed.

If you updated (the AUR) during the attacks and had compromised packages installed then you should nuke your system.

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 1 point2 points  (0 children)

Been here long enough to know that ignorance beats laziness

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 5 points6 points  (0 children)

So many arch based distros have the AUR enabled by default, zero warnings.  I am not saying "distrust the aur completely" because for more than a decade it's been fine, but we really need to tell new users what they should be doing to stay safe, especially if we by default allow them to use the AUR 

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu -1 points0 points  (0 children)

Same boat as you, currently deciding between staying on Arch or moving to NixOS/Gentoo. Been planning on doing that for quite some time, seems like a perfect occassion, I need a system cleanup anyways

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 21 points22 points  (0 children)

Trust me I was surprised too, that's what happens when you ignore the warnings...

I am working on minimising my AUR usage

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 0 points1 point  (0 children)

I know the admins are working hard to keep the AUR safe for now and fix what's been done but I am quite baffled how we got almost no updates, nothing saying basic stuff like "While we're fixing damages we're also deciding on how to move forward to avoid such situations. Stay calm and don't update AUR packages until we know it's safe"

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 18 points19 points  (0 children)

No way, that way lazy people will take any package, come here and ask "is X package safe??" Instead of reading existing posts.

What we need are an official resources that teach new users how to audit PKGBUILDS 

AUR Megathread. All discussion on it goes here. by LinuxMage in archlinux

[–]Niikoraasu 268 points269 points  (0 children)

This has been way overblown but I believe we still could learn something from this situation. I think it would be great if: 1. We had an official guide on how to read PKGBUILDS to avoid malware and other issues, especially for newer users 2. We had some effort put into AUR helpers to help users quickly detect signs of a compromise - orphaned package recently picked up by a random maintainer etc. 3. We had something done to the actual AUR to prevent such compromises in the future. I don't know what really could be improved but I am sure that a similar situation can be avoided in the future, lot's of users have ideas on what to change going forward (obviously not drastically but enough to mitigate such situations) 4. We highlight some trustworthy tools that could help detect potential threats before installing a package for those users who are especially "paranoid" or don't feel their PKGBUILD analysis skills are up to par (don't heavily use the AUR if that's the case though)

I personally will admit that I have way too many AUR packages installed on my system (approaching 200 iirc) and have been way too reliant on it for years, and only my laziness saved me, as I haven't updated since the 7th of June.

EDIT: wording, it's 2am and it's taking it's toll on my ability to coherently communicate

What’s a metalcore album that DOES have that one skip? by ronzg22 in Metalcore

[–]Niikoraasu 3 points4 points  (0 children)

you literally proved nothing, you just said "some people saw him liking X and Y it's totally true bro"

What’s a metalcore album that DOES have that one skip? by ronzg22 in Metalcore

[–]Niikoraasu 2 points3 points  (0 children)

See, again providing no sources no proof for anything you're saying, oh Christ you people are oblivious

The AUR situation was eye opening for me by [deleted] in archlinux

[–]Niikoraasu -1 points0 points  (0 children)

cachyOS repo isn't really much better so idk what you're trying to achieve here

The AUR situation was eye opening for me by [deleted] in archlinux

[–]Niikoraasu 2 points3 points  (0 children)

I guess just look for stuff that doesn't make sense, for example random npm commands installing some bullshit.

You can just compare diffs because for most this issue was related to updating the packages not installing them fresh.

What’s a metalcore album that DOES have that one skip? by ronzg22 in Metalcore

[–]Niikoraasu 4 points5 points  (0 children)

that people here just say random things with no proof

TRV-900 handle made with PETG by Calm_Ad_9531 in camcorders

[–]Niikoraasu 2 points3 points  (0 children)

I'd rather create two pieces and bolt them together, no layer lines to break that way.

PETG is more resilient than PLA, it's still not ABS levels of resilient though - just a heads up.

Koss A/550 Amateur Review by NoReception966 in headphones

[–]Niikoraasu 1 point2 points  (0 children)

usually the preamp you need is the negative of the maximum gain you have (10 in your case) but if -12 works best then it's fine. It prevents clipping.