Guide To Arch Linux User Repository Safety

Guide To Arch Linux User Repository Safety

Brodie Robertson

1 год назад

18,481 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

dirty dog
dirty dog - 05.03.2023 22:14

I use the AUR and a aur helper, been very lucky so far

Ответить
bigmike obama
bigmike obama - 19.02.2023 06:52

the only problem i have ever had on the aur is an application that hasnt been updated in a long time and just doesnt do anything. nothing has ever broken my system

Ответить
ZeoCamo
ZeoCamo - 20.01.2023 17:24

the AUR is 100% safe, no problem what so ever, just as safe as android's store :D ..... I use Arch BTW

Ответить
Carlos Lopez
Carlos Lopez - 12.12.2022 18:32

Thank you for this vid Brodie, starting to test Manjaro and saw a few things missing. Now I know a little more about what to watch out for

Ответить
Boris S.
Boris S. - 08.12.2022 21:26

Yes, I like this video! 👍 Thanks!

Ответить
Mitsunee
Mitsunee - 07.12.2022 20:26

Personally, I have no idea why I watched this video. I mean I basically do the same thing with npm packages, so I guess I agree with you magic arch man.

Ответить
spicy noodle
spicy noodle - 06.12.2022 22:10

I see many people stating that they barely use the AUR and I simply don't trust them. There's basically no benefit to Arch when we discard the AUR. There are plenty of up-to-date distros like Fedora that would get the job done better than AUR-less Arch

Ответить
J.P.
J.P. - 06.12.2022 18:15

I use AUR as a Manjaro (GASP!!!) Unstable user.
I'm watching this, 'cause it was in my feed :P

Ответить
Johann
Johann - 06.12.2022 14:50

I have no idea why I am watching this video - subscribed.

Ответить
KpopCraftster
KpopCraftster - 06.12.2022 14:42

As someone who avoids using the AUR unless absolutely necessary, I think you may be overestimating how many arch users bother with the AUR and especially how many chose arch because of it.

Ответить
Capability Snob
Capability Snob - 06.12.2022 11:37

Sweet, so to slip a keylogger into the AUR, I need to make sure the download URL, developer name, and install script check out. I'll assume nobody will bother to read the source if it's ugly enough.
Not that this isn't good advice - it's just a shame that I can't use my expensive sliver of magical melted sand to comprehend and manage what the package can or can't do. Like, we need a lavamoat for system packages.

Ответить
natto
natto - 06.12.2022 07:57

just use nixpkgs bro

Ответить
No tux no bux
No tux no bux - 06.12.2022 05:54

I have a few aur packages and I host the code on my own server. I have no idea if anybody has actually read the code to see if it's actually not malware.

Ответить
fabricio
fabricio - 06.12.2022 04:46

Do You Wanna my Sincere Opinion? Arch Linux Sucks..its just a "Linux Mint Slackware For Hipsters",this distro is for Masochists thats wanna be cool,but never will be cool....The Real World Linux distros are 100% muche Better....

Ответить
Aoitori365
Aoitori365 - 06.12.2022 04:20

Eyy you are

Ответить
Rob Geib
Rob Geib - 06.12.2022 04:13

Great tutorial on how to critically think about what you are installing.

Ответить
negative
negative - 06.12.2022 04:06

heres how i keep myself safe when using the AUR. 1. Clone the AUR repo. 2. edit and modify PKGBUILD and get rid of libsystemd,systemd dependencies, 3. then install with makepkg -si. Systemd for most if not all of the packages are just garbage and basically unnecessary for package functionality.

Ответить
Craig W
Craig W - 06.12.2022 03:07

Good basic instructional video Brodie. IMO, too much AUR will eventually break something on a newby setup. Always best to stick to the pacman repo as much as possible. When not possible, the AUR kicks butt and makes life quick and easy.

Ответить
Starlord Stavanger
Starlord Stavanger - 06.12.2022 03:04

What kind of tea do u drink bro? im sipping on some chocolate mint right now but in the mornings i do love me some earl grey or english breakfast :)

Ответить
ax trifonov
ax trifonov - 06.12.2022 02:44

Now i want to learn the same about flatpaks and snaps.

Ответить
Jonathan Brouwer
Jonathan Brouwer - 06.12.2022 02:36

What is your paru config? The review screen with the file tree looks pretty cool

Ответить
Vaisakh K M
Vaisakh K M - 06.12.2022 02:04

Now WHAT I DO WITH 1000s of PACAGES i installed from aur with out looking at anything.... :(

Ответить
CMDR Sweeper
CMDR Sweeper - 06.12.2022 02:00

Well I am an AUR helper user... Even on my arch homeserver I now use an AUR helper.
Just doing the updates and making sure the zfs scripts like sanoid stays up to date is reason enough for me.
So my tactic on the AUR and the mess you can get, is that I try to use it as sparingly as possible... But the ZFS snapshots stuff just became super needed to avoid data paranoia so...

Ответить
zen
zen - 06.12.2022 01:12

so for every package you want to install from the aur, you should audit the package build script? sounds like a bit of a hassle.

is there any kind of reputation or rating system for aur package authors? or is that too easy to game with bots?

Ответить
Tuxpeng
Tuxpeng - 06.12.2022 01:11

Not to heavily actually, most of the packages are actually from the main repo or chaotic-aur

Ответить
Dreamcat 4
Dreamcat 4 - 06.12.2022 01:01

i want to see cli tools for installing aur pkgs doing more of these checks automatically. because when you really work it out, a lot of the stuff you are manually checking here in this video... it could be given output to flag and inform the user. kindda like a linting process. for example if the src repo url is not an identified domain or self hosted that could print out a notification line in a shade of yellow. to prompt the user to manually check. or if the github repo is a fork. or if the github username does not match the aur username. then how many comments. and can automatically score those aur comments with sentiment analysis tool. and the upvotes. and then if flagged for deletion that could be printed in red color. all so many of these checks can and should be automated. with verbosity levels as to how much details to print. and user settings to decide how paranoid you want to be.

another feedback on cli can be to tell the user if the package maintainer is not using or has not enabled 2fa. since this is also another good extra security measure. to stop insecure aur accounts from getting hijacked. the same thing should in fact also extend to the repo accounts of the src on github or gitlab. we need reporting that those upstream accounts where we are actually fetching the software from... the end user must also be told whether those developer accounts are being secured properly by 2fa. so that (again) the person downloading can decide and the ability to choose what their own local security policy is they want to follow. this is especially important for open repos like aur. were anybody out there can submit software and packages

Ответить
LeoVi
LeoVi - 06.12.2022 00:32

I am a fedora user, and I feel it's kind of, unnecessary? But hey good luck

Ответить
SlideRSB
SlideRSB - 06.12.2022 00:26

I like using pamac as my AUR helper because I like how it DDoSes the AUR.

Ответить
rochr4
rochr4 - 06.12.2022 00:22

review launches lf? do share this.

Ответить
Michael Mantion
Michael Mantion - 06.12.2022 00:11

When you install on paru you don't need the -S

Ответить
Franco Castillo
Franco Castillo - 06.12.2022 00:10

I like to listen to the high-pitched voice of this boy 😅😅😅

Ответить
Anix
Anix - 06.12.2022 00:08

I dont know what should i choose? An binary AUR packages ungoogled chromium i.e ungoogled-chromium-bin OR a repo from Opensuse special for Arch Linux. Github page from both sources are the same.

Ответить
Erik Lundstedt
Erik Lundstedt - 06.12.2022 00:02

Back when I was using Debian, I wrote a utility in bash to look for packages using fzf (script <part of package name> ==> fzf to find the right package ==> install)

Nowadays I use a package called parui that works almost the same way (no fzf ☹️) and it's pretty great

It is dependent on paru afaik so keep that in mind

Ответить
Josh Doing Linux
Josh Doing Linux - 06.12.2022 00:01

I unfortunately live in an area where we’re not taught about safety devices and safe “browsing”. My parents were uneducated about modern safe browsing methods and so I had to explore the aur for myself and make my own mistakes and deal with infections I was unprepared for.

Thanks for posting this Brodie I couldn’t resist the euphemisms.


/s

Ответить
dozen
dozen - 05.12.2022 23:59

I recently spent some time learning how to use steamtinkerlaunch & ended up needing to use the AUR to install it bc all the other options were WAY too involved for me, & I wondered about this kind of thing at the time! These are great tips; I think they'll be easy to remember and probably make me feel a little bit less like I could be playing with forces I don't understand, lol.

Ответить
Peanut - INTP
Peanut - INTP - 05.12.2022 23:56

If installing random software is wrong, watching random YT videos (like this one) must be wrong too. 🤔
I need to rethink my entire internet usage.

Ответить
daru
daru - 05.12.2022 23:49

The thing I don't like about aur is that some people put there their work and you are unable to install it because it asks for password. Why is it then there?

Ответить
Jeff Story
Jeff Story - 05.12.2022 23:31

github cody_learner aurch

Ответить
YAMI
YAMI - 05.12.2022 23:10

virgin check install script vs chad test build installer

Ответить
xslvrxslwt.
xslvrxslwt. - 05.12.2022 23:03

No thanks, i prefer [testing] [chaotic-aur].

Ответить
XeroOl
XeroOl - 05.12.2022 23:02

I would love to see the same mentality toward vim plugins. It seems like a lot of people got the memo on AUR packages, but not yet for vim plugins. Nobody reads the diffs :)

Ответить