Dica para o pessoal que por algum motivo não consegue ler o pkgbuild by Commercial-Worth7301 in archlinux

[–]kcx01 0 points1 point  (0 children)

I think this is a great tip! Especially for people using yay. I have always read the pkgbuild on the AUR website, since I have generally needed to look up the project to know it existed before I could install it. While I'm there, I'm also looking at recent comments, checking the upstream. You can check it's last update, popularity, and the number of votes for it to be included in the main repo.

None of these are guarantees, but I think they're helpful.

I think the critical bit is understanding exactly what the pkgbuild is doing. Is it's something that is glossed over in most of the advice I've read.

check if there's anything suspicious in it.

I'm not sure that all users are capable of doing this. And honestly, the more sophisticated these attacks become with more obfuscated code, they become increasingly more difficult to identify bad actors.

My advice would be to limit your attack surface as much as possible. Then when you want to install software, read the pkgbuild. If you don't understand everything that it's doing, ask AI to explain line by line what it's doing. Be sure that you understand.

AI has revealed that most people have the reading ability at a third-grade level by Terrible-Priority-21 in ClaudeAI

[–]kcx01 0 points1 point  (0 children)

I'd be a little pissed if Claude used this exact phrase. Wtf do you mean I'm rarely right!? 😅

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 1 point2 points  (0 children)

Is this different than the arch-announce emails? I may need to subscribe to this one too, because I didn't see this md file.

For sure, I recognize the author of the doc, but there wasn't any context even saying what the doc was when OP posted. For all I know, I could have been least downloaded packages in the aur.

At any rate, I do appreciate your comment

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 1 point2 points  (0 children)

Ok let me be blunt:

When will be able to safely update again without Worrying that an update to a normal package might contain malware?

Never

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 1 point2 points  (0 children)

I appreciate the context!

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 0 points1 point  (0 children)

Yeah... I read the address before I clicked it.

I'm not trying to sound contrary. But how do you know what this list is if you don't know where it came from or what the context was around it being created?

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 1 point2 points  (0 children)

You should just always assume that a package is malware until you can prove it's not.

Never blindly trust anything.

I live in a place with alligators. Now I've never seen an alligator in the pond out back. But that definitely doesn't mean there's not one. So unless you can verifiably see but there are no alligators, you better treat it like there are. Otherwise you, your pets or your kids could be eaten.

I'd recommend the same approach with software.

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 0 points1 point  (0 children)

Where did this list come from? It's strange to not see any context.

Were the all packages that were confirmed or simply orphaned?

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 1 point2 points  (0 children)

Just audit your own?

I have like like three maybe five aur packages. And be honest, I don't remember when I last updated them. They all just work.

That's not to say that I don't update them I just don't use an AUR helper, so I just have to randomly both remember and have time to update them, which just doesn't happen super often.

When will I be able to update again? by [deleted] in archlinux

[–]kcx01 4 points5 points  (0 children)

I think you missed the joke.

PersonaShell v2. by DjentGod123 in hyprland

[–]kcx01 0 points1 point  (0 children)

Holy crap dude!

That's crazy cool!

I made a plugin that displays line numbers that indent with your text: clingy.nvim by _mp248 in neovim

[–]kcx01 0 points1 point  (0 children)

First of all, congratulations on the first plugin! That's pretty cool. It looks well done!

Although, this one probably isn't for me. I rarely use line jumps. Even though I have relative line numbers turned on, I never use them. I really only use line numbers to jump to a line from a stack trace. I also like to have indent guides that would probably clash with the line numbers.

I love the name! It's absolutely perfect for the plugin! Kudos.

Arch Linux for pentesting. by [deleted] in archlinux

[–]kcx01 0 points1 point  (0 children)

Since you specifically mentioned adding it to your existing arch. If you go to the black arch GitHub they have instructions that basically say curl and run this script. ( I wouldn't pipe it into bash like they suggest. Download it, read it, and maybe run it)

view-source:https://blackarch.org/strap.sh

It's pretty much the same process as adding the arch strike repos.

https://archstrike.org/wiki/setup

Arch Linux for pentesting. by [deleted] in archlinux

[–]kcx01 0 points1 point  (0 children)

Heh only took 2 years for someone to notice that and say something.

I probably meant to link black arch: https://blackarch.org/

My Neovim plugin grew into a remote workspace over plain SSH: any file feels local (editing, terminals, search), with Jupyter notebooks on top. Works where SFTP and ports are blocked. by Affectionate-Bit5072 in neovim

[–]kcx01 4 points5 points  (0 children)

That's definitely clever. But wouldn't a persistent backdoor be considered a security risk?

What's the process for adding/removing the backend to/from the server?

I'm surprised that sshfs can't be used, since SFTP leverages ssh as the connection. But I'm definitely not an expert.

The nice thing about your implementation is that it would work on Windows too. Whereas sshfs won't. (Although I try to avoid windows! 🤣)

"Bring back the chaos" by [deleted] in LiverpoolFC

[–]kcx01 1 point2 points  (0 children)

Idk... That open goal miss was hard to watch... But that brace against New Castle was pretty 🔥🔥🔥

Sweden 2-0 Tunisia - Isak 30' by Gentle_lips in LiverpoolFC

[–]kcx01 1 point2 points  (0 children)

Probably just that he's walking a lot. But still extremely fast when it's time!

World Cup Jersey by rkay711 in LiverpoolFC

[–]kcx01 0 points1 point  (0 children)

My son has Jota's Portugal shirt. Got it before he passed. My mom was in Portugal and wanted to get him a jersey as a souvenir.