On the Arch User Repository, and the complacency for crap
i use malware btw
he AUR got hit with a malware attack. Again. Normally, one would look at this, lock it down, and figure out what is broken and how one can go about fixing it, but it seems like Arch users want things to stay as they are instead.
And that isn’t an option when the fucking thing is a broken turd of a system.
The AUR is insecure for no good reason
Generally, if you use the AUR, you’re expected to read the PKGBUILD, which – okay fine. But that is still no excuse for just how insecure the AUR is. Why are there still no guards against flooding the AUR with orphaned packaged adoptions? Why are commit signatures not enforced, which helps prevent impersonation? Yeah, because of the way Git works where you can fill any user/email, and because signatures are not enforced on commits to repositories on the AUR, someone who abandoned a package was impersonated in the latest wave. Simply put, putting all responsibility on the user is not an excuse for crap security, and anyone who says this is an absolute moron. The latest cope from Arch users is claiming that the AUR is a glorified pastebin, which is still not a valid excuse in the slightest. Again, why does this excuse the AUR having such poor security? I’m asking as a former Arch user, someone who did check the PKGBUILD when using the AUR.
There’s this inherent lack of empathy from Arch’s devotees towards people who may have not been aware of the implications of using the AUR, and it’s branded as “the hard truth”. What the people defending this crap leave out is that the AUR is your only place to use popular packages without a proper redistributable license without the overhead and clunkiness of Flatpak sandboxing, or drivers that would still be in use due to the hardware’s prevalence. You can’t be both a hub for some of the most popular apps while saying said hub is unsupported and you shouldn’t actually use it. Popular and well-known packages that are included on the AUR include JetBrains IDEs, Visual Studio Code, the official Minecraft Launcher, Zen Browser, Waterfox, and NVIDIA drivers for 10xx-series GPUs that Arch no longer supports. The latter I could understand if other packages no longer supported by their upstream vendor were removed, but Arch still has .NET 6 in their official repositories despite Microsoft dropping it in late 2024. (NVIDIA 10xx users may want to try Bazzite or even just Ubuntu, or stick to Windows, where as of now NVIDIA still supports it on Windows 11)
Also, no-one is infallible. Like, sure, you can check a PKGBUILD, but what about the dependencies outside of Arch? Some of these waves hitting the AUR used NPM, Node.js’ package manager. Not everyone is going to be an expert on what looks correct or what is suspicious, a lot of people don’t have the time to check every minutiae of a package, and someone could also be having a bad day and not checked something properly. And people simply don’t have the time to check every minutiae of a PKGBUILD. Mistakes are inherent to humanity, and no-one is infallible. If these people got hit in these malware waves, I highly doubt they’d be saying the shit they’re saying.
The AUR is also used as an official distribution method for Minecraft’s official launcher, as well as 1Password. There’s a bunch of mixed messaging going on not just from vendors like those two, but Arch as well. The Arch Wiki implicitly recommends the use of AUR packages the moment they list an AUR package on their list. If the AUR is really that unsupported, then Arch is basically saying “no, you can’t use one of the most popular text editors, use the official launcher for one of the most popular games of all time, use one of the most popular password managers, run a Firefox alternative, or even use your old yet still-working GPU on our distro, what are you stupid?”.
How other Linux distros + Windows does it
Even as I used the AUR, I knew in the back of my mind that this was dodgy as fuck, and part of the reason I used Cachy during my final times with Linux was because it had some packages on their own repositories that’d be stuck on the AUR otherwise, and they were checked for malware or other suspicious changes.
A lot of distros handle community/user-run repositories by making it so all you need to do is trust that the maintainers are reputable. Examples include PPAs on Debian/Ubuntu, COPR on Fedora, Open Build Service on openSUSE, and overlays on Gentoo. These are essentially just small repositories managed by one or a few users, rather than a bunch of git repos anyone can take over. While they’re still not infallible and have had run into issues with malware themselves, it’s still better than the Wild West the AUR is due to the trust system involved. It’s also worth pointing out that two other OSes have an “AUR-like” repository of package scripts: Gentoo, via the GURU overlay, and Windows, via Winget. GURU’s rules stipulate that the repo has three layers of contributors, enabling a chain of trust. Winget uses whatever technological and human measures they can to enforce security for package maintainers including the enforcement of commit signatures, and it doesn’t seem like anything too fancy or proprietary to Microsoft. Anyone can implement these measures. Both of them act on one centralised repository where these attacks won’t scale well rather than a bunch of tiny repositories, and both correctly assume that the user needing some responsibility when handling these packages doesn’t absolve them of any security faults.
To add onto this, due to the nature of how Gentoo packages can be delivered, Gentoo has a lot of officially maintained packages that would’ve ended up on the AUR. Spotify has been available on the Gentoo repos for years, well before Arch resorted to spotify-launcher (both solutions repackage the official .DEB to skirt around the lack of a redistributable license). That and the overlays being in a similar vein to COPR and PPAs result in a vastly smaller surface level for malware. Void Linux acts similarly to Gentoo by not building all of its official packages in xbps-src, telling users to build those themselves. I can’t see a reason as to why Arch can’t just have an official git repo for officially managed packages they can’t redistribute as a binary package, when two distros less popular than it already have a decent system for handling this.
Man, I didn’t think that hopping phase during COVID would’ve actually benefited me somehow, lol.
The complacency for crap
And here’s the problem I have with Linux and the community that drives it.
It’s one thing to point out that Microsoft implemented a better system for community-run package maintenance, given that Microsoft has infinitely more money to throw at than Arch even with the Valve sponsorship. The thing is, a less popular distro also implemented a better system, and came to the same conclusion as Microsoft when it came to responsibility, yet people are coming out to defend the AUR and put all the blame on the user rather than the thing that is objectively broken.
It exposes one of the problems I have with the Linux community, and why I don’t think Linux will ever be suitable for the desktop (at least, not for me). It’s this complacency. Not even for subpar paradigms like a GUI that isn’t well built, although GIMP has its defenders despite one of their developers telling me that they want to make its UX better, and requesting me to share their efforts on Bluesky (which I have). It’s complacency with blatantly broken crap like this. This complacency for crap is also why GIMP has an awful reputation despite its developers willingly striving for better. It’s why people are resorting to LLMs when they have issues with Linux, instead of asking actual people. It’s also a FOSS thing in general – this is also why the Fediverse has failed to make any meaningful waves in adoption while Bluesky had more gains in popularity, because any improvements to ActivityPub or the many fedi services are scoffed at by its biggest evangelists.
It’s the inability to learn from Linux’s (and FOSS’ in general) failings, and the complacency for crap that pisses me off.
And, maybe I shouldn’t care about this, this much. Like, I use Windows now and I’m getting a Mac this month. AUR malware isn’t a problem for me, because I don’t use Arch anymore (unless you count SteamOS? lol) and after this I am actively avoiding it where possible, including derivatives like CachyOS, unfortunately.
The thing is, I would love to use the Linux desktop as a daily driver. KDE is still the best desktop I’ve used so far and if it weren’t for the fact that MusicBee isn’t on Linux and is pretty clunky on WINE I’d probably have stuck on there. I like a lot of what Linux does, and I want to appreciate what free and open-source software is capable of, but I don’t delude myself. I know there are things that are inherently broken about the ecosystem, just like there are things broken with and the best people in the community are the ones that know that. If these communities don’t strive for better, the Linux desktop will stagnate and the only people who will use it are weird nerds and toxic cultists which is not the audience desktop Linux should be striving for.
If you disagree with this, then you can stay deluded and have your malware-ridden shithole, while the rest of us works with something that isn’t a steaming pile of shit, whether it’s Linux or not.
I would’ve put this on the main post I have about Linux problems, but that’s more for desktop Linux in general, not so much a specific distro. At least I have something I can point to, when the next malware wave hits.
Oh, and as for LLM-based solutions for detecting malicious code? Speaking as someone who doesn’t mind LLMs, I don’t think Arch should resort to that right now. They need to focus on getting the AUR up to scratch security wise without resorting to scanning via machine learning.
Did you enjoy this article?
Recommend it — Standard Reader surfaces well-loved writing to more readers across the network.