D•Scribe
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@europe.pub to Linux@programming.dev · 2 days ago

Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack

www.phoronix.com

external-link
message-square
22
link
fedilink
  • cross-posted to:
  • libre@hexbear.net
  • archlinux@lemmy.ml
126
external-link

Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack

www.phoronix.com

cm0002@europe.pub to Linux@programming.dev · 2 days ago
message-square
22
link
fedilink
  • cross-posted to:
  • libre@hexbear.net
  • archlinux@lemmy.ml
  • Meshuggah333@piefed.world
    link
    fedilink
    English
    arrow-up
    39
    arrow-down
    2
    ·
    edit-2
    2 days ago

    The question here is why the f’ didn’t they shut down AUR packages takeover procedure? It makes no sense facing an attack of such a large scale.

    • caseyweederman@lemmy.ca
      link
      fedilink
      arrow-up
      4
      ·
      1 day ago

      It’s the USER repositories. If you go, right now, to aur.archlinux.org, the very first section on the page after the header says

      DISCLAIMER: AUR packages are user produced content. Any use of the provided files is at your own risk.

      That’s always been there and every official messaging I’ve ever seen about the AUR has conformed. Read the changelogs because everything in the AUR is just a shell script some stranger wrote.

    • Excel@lemming.megumin.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Why should they? AUR is still working as intended. It’s basically a public wiki of shell scripts, it was never intended to be secure in the first place. It has always been the user’s responsibility to review everything or avoid using it.

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • our Matrix group chat
  • !reactos@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 701 users / day
  • 1.46K users / week
  • 3.52K users / month
  • 10.4K users / 6 months
  • 13 local subscribers
  • 14K subscribers
  • 4.35K Posts
  • 33.8K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • UI: unknown version
  • BE: 0.19.18
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org