I wouldn't say that there's an organized attempt to "paint Linux distros as dangerous". It's just what happens when you have people being people (as we see here) and there are structural vulnerabilities to software supply chains.
It's a juicy target, and it's being exploited. We can either learn from it or continue to suffer.
This isn't even new. Hell, I remember when Linux Mint was hacked a decade or more ago. They compromised the forums, the disk image downloads, the whole shebang. I haven't used it since.
AUR has always been a risk and that wasn't the first attack of that kind. And here... Well, if it was coordinated, they would've picked a distro that doesn't prompt responses like: "Oh, mandriva still exists?"
>feel like there's some organized attempt to paint Linux distros as dangerous.
imo the only ones doing that are the ones that try to portray the AUR as more than it actually is. A pastebin for package builds with "run at your own risk" all over it. It would be more concerning if there wasn't anything malicious found ever other day.
i mean, they're succeeding. whether it's coordinated or not the conclusion is the same.
but i think "linux distributions are dangerous" is the wrong conclusion. the right one is to treat each distribution based on their own security practices, and not "linux" as a whole. one distro's bad practices doesn't make others unsafe any more than one distribution's good practices make other safe.
The real takeaway for projects and companies should be that someone having historically behaved in a logical and responsible way doesn’t guarantee that they’ll continue to do that for forever.
Good security architecture has circuit breakers, even for people who are generally high-trust.
stop trying to make AUR sound like a place that can be compromised.
it's literary a tetanus ridden landfill, by design!
it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work)
the fact that idiots (in the original sense of the word in Greek) made automatic installers that fools novices to think those are vetted distro packages doesn't make it so.
The arch team seems to think differently based on how they reacted to the compromise. Something doesn't have to be locked down from the start in order to be compromised.
Not being willing to knowingly and actively distribute malware does not mean they don't agree with OP. All the "use at own risk, no vetting" warnings all over the AUR and wiki support OPs claim if anything.
It's a juicy target, and it's being exploited. We can either learn from it or continue to suffer.
This isn't even new. Hell, I remember when Linux Mint was hacked a decade or more ago. They compromised the forums, the disk image downloads, the whole shebang. I haven't used it since.