• 1 Post
  • 156 Comments
Joined 3 years ago
cake
Cake day: August 23rd, 2023

help-circle
















  • Official packages are already vetted so they don’t need user scoping. They could just enforce user scoping in the AUR and use the provides array for resolving conflicts. Its not a perfect solution but there’s no such thing as perfect security, just better security.

    Also having an AUR helper that properly containerized the build step would be an even bigger improvement.


  • Arch is deliberately minimal making it a good base system in the same way Debian or Fedora is. It’s smaller, simpler, updates faster than the others and is far more configurable. It is however not built for the average user and most distros built on top of it that try to make it more “usable” are IMO pretty dangerous ideas. I think the only derivative i’ve tried that was good was SteamOS because they made it Atomic like nix or silverblue.

    None of this really has to do with the AUR. That was always labelled as “use at your own risk”. And to their credit they caught and addressed the attack within a day of it happening. Still, hosting user PKGBUILDs and leaving it to individual users to audit them is not a secure solution, its just punting on the responsibility.