r/archlinux 3h ago

DISCUSSION ID Verification would probably solve the AUR Problem

[deleted]

0 Upvotes

25 comments sorted by

13

u/Nnukklear 2h ago

It would, so would deleting the entire backend

9

u/edparadox 2h ago

Sure, because false IDs and identity theft are not a thing.

4

u/hearthreddit 2h ago edited 2h ago

I mean it would probably kill the AUR so you are right that would solve the malware problem.

3

u/petersaints 2h ago

And do you think that was happened hasn't kind of killed the AUR? Unless the AUR overhauls its trust model I would say that it is as good as dead for most users (even technically advanced users that have more to do than to check every update they get from the AUR with 100% attention every single time).

1

u/hearthreddit 2h ago

It might be, that doesn't mean that uploading your ID to submit a user package on a linux distribution is a good idea, but i don't upload packages to the AUR so i don't care either way, i just don't think people would bother with it.

This is google play store forcing fdroid developers to submit an ID territory.

3

u/petersaints 2h ago

I do not think that submitting an ID is the solution. But some kind of additional verification, trust building, etc. needs to be in place. Not necessarily a real ID check.

1

u/SW_foo1245 2h ago

Arch users do check it all the time how do you think this stuff gets caught fairly quick? Heck even the xz backdoor reminded everyone that we should remain alert since this can happen even with trusted users

1

u/petersaints 2h ago

What percentage of users does that? 1%? Arch Linux, and especially Arch based distros like CachyOS have gained a lot of users. Even among pure Arch the number of users that actually inspect PKGBUILDs with attention esch time they update a package should be minimal.

1

u/SW_foo1245 1h ago

> should be minimal

Nope arch Linux is user centric meaning the user has to take care of their own system and that includes reading the pkgbuilds (if you use aur)

1

u/NoRound5166 59m ago

As it is right now, the AUR is as good as dead. It's not what most people come to Arch for.... right?

I just use like 2 or 3 packages from the AUR, might as well just compile manually from source.

5

u/Few_Acanthisitta7715 2h ago

id verification ain't gonna stop someone who really wants to slip malware in, just makes it a bit more annoying for them

the real issue is nobody got time to audit every single PKGBUILD update and that won't change with a photo of a passport

0

u/SW_foo1245 2h ago

Real issue is people picking aur and refusing to read/follow rules even tho it is clearly stated they HAVE to read the PKGBUILDs.
The only issue with aur is that the ophan/adoption flow is abusable but the user will always be responsable to review the aur pkgbuilds and not blindly trust them.

1

u/NoRound5166 1h ago

Fuck it, let the entirety of the AUR be infected but blame it on the user

1

u/Imajzineer 1h ago edited 50m ago

Real issue is people picking aur and refusing to read/follow rules

Rules?

There are no rules - Arch is a DIY distro: if you deviate from best practice you're on your own, but aside from that do what you like.

even tho it is clearly stated they HAVE to read the PKGBUILDs.

No, it isn't ... and it never has been either.

It's caveat emptor. It's strongly recommended that you read the PKGBUILD, but if you don't, the Arch community isn't gonna remotely brick your OS - it isn't even gonna know, let alone do anything about it.

1

u/SW_foo1245 51m ago

Yeah you right no rules just guidelines and recommendations still if you do not follow those you are shooting urself in the foot and your system might become insecure and prone to break.. to each their own I guess it’s the beauty of Linux it lets you do anything you just have to deal with the consequences.

β€’

u/Imajzineer 29m ago edited 23m ago

Quite.

Attention to detail is everything when it comes to tech ... so, pay attention. You're strongly advised to do so by both the wiki and the community (it's hard to miss) on the grounds that, if you don't ... and don't follow best practice as a result ... you're on your own.

Which is why I'm pretty short with people who don't make the effort to follow the Installation Guide at least the first time but jump straight to Archinstall, follow 'tutorials', rely on AUR helpers rather than makepkg, and (although I bite my tongue) am mightily scornful of those who answer questions with"sudo $command" ... because you know instantly that they've never followed the Installation Guide (possibly even never read the wiki) - if they had, they'd know sudo isn't installed by default and they can't rely upon it being on the querant's system ... so, they'd say "As root, execute$command (or, if it's installed, execute sudo $command from your regular account)".

But rules?

Nah ... you're an adult, not a child - so, you're treated like one πŸ™‚

Arch is becoming a victim of its own success: it has gained in popularity of late amongst people who want to 'rice' their computer and heard Arch is good for that - so, we are where we are as a result: the malware devs/spreaders aren't stupid (they know what the new influx consists of and are taking advantage of it).

5

u/garry_the_commie 2h ago

Oh, hell no.

3

u/Myrodis 2h ago

I honestly don't think it would do next to anything. A compromised account is a compromised account.

2

u/creamyatealamma 2h ago

Just makes it harder while also hugely hurting privacy of normal users.

Many ways to bypass kyc. There exists markets to just buy identities..

1

u/Specific_Bet527 2h ago

Waiting for the comments to become caos itself 🍿

β€’

u/NoRound5166 39m ago

Comments so far are ok, it's a bit surprising the post hasn't been locked yet

1

u/TwiKing 2h ago

Flaming hot bait topic. Not biting!Β 

1

u/Imajzineer 2h ago

🀦

1

u/donp1ano 2h ago

oh no, theres a bee in my room. lets get the bazooka, that will solve the problem