Bhahahahaha - /g/ (#105960259) [Archived: 141 hours ago]

Anonymous
7/19/2025, 10:41:25 PM No.105960259
383853829
383853829
md5: 157ba5b1feb32197d35c648c4319aa41๐Ÿ”
>The absolute fucking state of Linux

https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/7EZTJXLIAQLARQNTMEW2HBWZYE626IFJ/
Replies: >>105960288 >>105960339 >>105960451 >>105960780 >>105960971 >>105961014 >>105961330 >>105961408 >>105961434 >>105961595 >>105961630 >>105961667 >>105962545 >>105962545 >>105963020 >>105963025 >>105963188 >>105963360 >>105963441 >>105963550 >>105964302 >>105964487 >>105964696 >>105966197 >>105966419 >>105967807
Anonymous
7/19/2025, 10:44:46 PM No.105960288
>>105960259 (OP)
brave chads can't stop winning
Replies: >>105961231
Anonymous
7/19/2025, 10:48:00 PM No.105960310
>We strongly encourage users that may have installed one of these packages to remove them from their system and to take the necessary measures in order to ensure they were not compromised.

What are the necessary measures?
Replies: >>105960342 >>105960352 >>105960937 >>105963460 >>105964356
Anonymous
7/19/2025, 10:48:39 PM No.105960314
1730223124915655
1730223124915655
md5: 80bd103130aebeffffd705333bca6844๐Ÿ”
mfw when I run Windows instead and haven't install updates for 3 years.
Anonymous
7/19/2025, 10:50:13 PM No.105960323
reminds me of the xz back-door that got archtroons last year
Replies: >>105961579
Anonymous
7/19/2025, 10:52:45 PM No.105960339
>>105960259 (OP)
>AUR
not my problem with official Debian repo for Librrwolf
Replies: >>105962938
Anonymous
7/19/2025, 10:52:53 PM No.105960342
>>105960310
Backup, reformat, reinstal, pray to god that your BIOS/UEFI isn't permanently fucked.
Replies: >>105961272 >>105963056
Anonymous
7/19/2025, 10:54:08 PM No.105960352
>>105960310
Delete every social/work related account, and then remove and dissolve the hard drive and the motherboard in acid
Anonymous
7/19/2025, 11:04:48 PM No.105960451
1751381905612082
1751381905612082
md5: 1eb0ca2a6b3ab64762b1ba2a85027640๐Ÿ”
>>105960259 (OP)
One must be extra retarded to install these literally who sus packages. Its like
>Find a AUR pack named firefox-AIDS-bin
>Made two days ago by a random fag
>Go ahead and install it anyway
>Get Arch AIDS
>WOOOOOWWWW
Its mostly a nothingburger, but Im sure some retards went ahead and installed them without looking into it. Using AUR requires common sense.
Also, the community detected that shit pretty fast, so AUR is doing alright.
However, if Linux popularity increases, then AUR will become more vulnerable, so Archtroons will need to come up with some ideas to secure AUR. The vigilant eye of the community can only be vigilant to an extent
Replies: >>105961350 >>105961393 >>105961410 >>105964479 >>105964674
Anonymous
7/19/2025, 11:12:11 PM No.105960504
that's what you get for using operating systems ran by hobbyists and volunteers
Anonymous
7/19/2025, 11:18:00 PM No.105960541
This kills Arch Linux
Anonymous
7/19/2025, 11:20:18 PM No.105960558
linux desktop is dying.
Replies: >>105961282
Anonymous
7/19/2025, 11:50:08 PM No.105960780
>>105960259 (OP)
I will remind this fact to loontroons the next time they call old windows "insecure".
Replies: >>105960983 >>105961325
Anonymous
7/20/2025, 12:10:10 AM No.105960937
>>105960310
TN: the needful
Anonymous
7/20/2025, 12:14:26 AM No.105960968
maybe linux devs should think about security as much as they think about their genitals
Anonymous
7/20/2025, 12:14:37 AM No.105960971
>>105960259 (OP)
Are AUR packages audited before being accepted to the repository?
Replies: >>105961126 >>105961231
Anonymous
7/20/2025, 12:15:46 AM No.105960983
>>105960780
old windows doesn't receive security updates, so the vulnerabilities remain there
Replies: >>105961730
Anonymous
7/20/2025, 12:18:48 AM No.105961014
>>105960259 (OP)
This is only an issue if you explicitly installed them right? They didn't hack the maintainer of some already existing package and replace it with malware right? It was new stuff uploaded by a literally who new user out of nowhere?
Replies: >>105961126 >>105961370
Anonymous
7/20/2025, 12:30:23 AM No.105961126
>>105960971
No, why would they be.
>>105961014
Yes you would have to be a massive retard to be affected.
Anonymous
7/20/2025, 12:40:21 AM No.105961231
>>105960288
>>105960971
No and that is advertised heavily.
Using the is as secure as downloading from rando websites
Anonymous
7/20/2025, 12:44:16 AM No.105961272
>>105960342
>pray to god that your BIOS/UEFI isn't permanently fucked
wait they can do that ?
Replies: >>105961312
Anonymous
7/20/2025, 12:45:16 AM No.105961282
>>105960558
wrong, it just went over 5% in the US
Replies: >>105964644
Anonymous
7/20/2025, 12:48:10 AM No.105961312
>>105961272
With root access, of course.
Anonymous
7/20/2025, 12:49:57 AM No.105961325
>>105960780
You can install malware even on the latest version of windows if you want.
Replies: >>105961605 >>105961730
Anonymous
7/20/2025, 12:50:21 AM No.105961330
aur
aur
md5: 6cfe9facbd37c3934966eb5e816363ab๐Ÿ”
>>105960259 (OP)
People that have no idea what the AUR is are gonna shitpost this to death for the next few weeks. This isn't even the first time just the most recent.
Anonymous
7/20/2025, 12:50:30 AM No.105961334
Why the fuck does Arch exist?
Anonymous
7/20/2025, 12:52:03 AM No.105961350
>>105960451
How about just don't use aur if you don't know how to audit the files. You aren't even gonna get support if you use aur.
Replies: >>105961369
Anonymous
7/20/2025, 12:54:18 AM No.105961369
>>105961350
People usually download AUR pacs because they are "ricing up" their Arch experience, which is not only stupid, but a waste of time. If you want to use AUR, use it only for official shit
Anonymous
7/20/2025, 12:54:22 AM No.105961370
>>105961014
Yeah. It only got you if you installed these packages, which is unlikely as they were found and removed very quickly.
This happens every now and then. Read the PKGBUILDs, make sure they only pull from a git that you trust, and after that it's no more dangerous than running something from Github like normal. That's where most OSS comes from anyway.
Anonymous
7/20/2025, 12:56:36 AM No.105961393
>>105960451
snapshots should not be allowed to be uploaded to AUR with zero oversight. Someone should at the very least take a cursory glance and make sure it checks out. But probably the Arch team disagrees with that.

The more conservative approach would be not to have an AUR at all and just have wiki entries with installation instructions for how to install all those unsupported packages manually.
Replies: >>105961451
Anonymous
7/20/2025, 12:58:04 AM No.105961408
>>105960259 (OP)
Thank G*d I used Debian
Anonymous
7/20/2025, 12:58:12 AM No.105961410
>>105960451
>the community detected that shit pretty fast
Yes, and that proves it's fairly secure.
If this went unnoticed for months we'd have reasons to complain but they fixed it in a couple of days so they did good.

As for improvements I think they could implement a "peer review" system where everything has to be scanned by someone else before it gets accepted on the AUR.
Replies: >>105961429
Anonymous
7/20/2025, 1:00:01 AM No.105961429
>>105961410
>think they could implement a "peer review" system where everything has to be scanned by someone else before it gets accepted on the AUR
Yeah, Im thinking this is probably the future of AUR now that linux are picking up in popularity thanks to Microjeet and Steam Deck. Packages will be tested by the community first, and then they will be uploaded on the site
Anonymous
7/20/2025, 1:00:42 AM No.105961434
>>105960259 (OP)
it's easy to not risk shit like this: just don't be a tranny and use an actual OS for sane people
Anonymous
7/20/2025, 1:02:08 AM No.105961451
>>105961393
>install all those unsupported packages manually.
That makes it LESS secure not more.
The AUR is a step up from installing software from a random website or Github page.
Replies: >>105961488
Anonymous
7/20/2025, 1:05:21 AM No.105961488
>>105961451
Not really, AUR pkgbuilds just pull from those "random websites" or github (i.e. the software's official website/github) in the first place and automate the installation.
Replies: >>105961559
Anonymous
7/20/2025, 1:16:58 AM No.105961559
>>105961488
Malware gets removed from the AUR.
This story proves this.

When you host malware on your own website nobody can take it down.
Your server, your responsibility.

Not sure how Github handles malware to be honest.
Anonymous
7/20/2025, 1:20:33 AM No.105961579
>>105960323
That affected testing versions of Debian and Fedora. Arch says it never affected them, dunno if that's cope though.
Replies: >>105961603 >>105964570
Anonymous
7/20/2025, 1:22:21 AM No.105961595
>>105960259 (OP)
>patch
>patched
>fix
Imagine not thoroughly inspecting AUR source files, let alone building AUR packages named like this without eyebrows being raised
Anonymous
7/20/2025, 1:23:24 AM No.105961603
>>105961579
It infected Arch but did not activate on non-deb/rpm systems
Replies: >>105963034
Anonymous
7/20/2025, 1:23:31 AM No.105961604
We told you to install Gentoo. We told you to compile your own binaries.
We told you and you didn't listen.
>Arch
Not even once.
Anonymous
7/20/2025, 1:23:41 AM No.105961605
>>105961325
No you can't linuxtard, Microsoft Defender is literally there so malware can't get in
Meanwhile troonix doesn't have anything similar
Replies: >>105961646 >>105961678
Anonymous
7/20/2025, 1:28:09 AM No.105961630
5643565534
5643565534
md5: 94a090d47fb707aaa92c5ac5240f1e93๐Ÿ”
>>105960259 (OP)
i will never understand updateniggers.
can't you just disable updates in arch?
Replies: >>105961643 >>105961704 >>105961731
Anonymous
7/20/2025, 1:30:04 AM No.105961643
>>105961630
Yes, you update whenever you want. But it's an updooter distro, the whole point is to updoot.
Replies: >>105961671 >>105961682 >>105963174
Anonymous
7/20/2025, 1:30:34 AM No.105961646
>>105961605
I had to remove malware from my boomer dad's Windows laptop twice.
Anonymous
7/20/2025, 1:32:34 AM No.105961667
>>105960259 (OP)
manjaro wins again
Replies: >>105961704
Anonymous
7/20/2025, 1:33:10 AM No.105961671
>>105961643
sounds terrible, last thing i would want after tinkering for ages with the OS is to get rekt by some pajeet using chatgpt to sneak spyware into an update
Replies: >>105961690
Anonymous
7/20/2025, 1:34:15 AM No.105961678
>>105961605
you know windows is malware at this point, right?
Anonymous
7/20/2025, 1:34:33 AM No.105961682
>>105961643
>install Arch
>get system running nice
>"hmm, how do I update just my browser and keep the rest of the system stable?"
>install Debian
Anonymous
7/20/2025, 1:35:12 AM No.105961690
>>105961671
Ah well updooting actually has nothing do with this malware incident. Updates from official repos have never been a security issue afaik, except for the infamous xz backdoor last year.

The issue here is this AUR which allows people to upload malware with zero oversight until after it's been online for some time.
Replies: >>105961752
Anonymous
7/20/2025, 1:36:55 AM No.105961704
>Removed in less than 48 hours
Yeah it's over for us.
>>105961630
This has nothing to do with updating. Somebody uploaded some shit with a legit-sounding name and then it was removed.
>>105961667
Actually retarded.
Replies: >>105961712
Anonymous
7/20/2025, 1:37:39 AM No.105961712
>>105961704
baited
Anonymous
7/20/2025, 1:39:31 AM No.105961730
>>105960983
Literally won't do shit, since your computer is by default firewalled by your ISPs router. You can also install software from an offline installer that has all its dependencies included, unlike loontroons that need to be connected to the (((((cloud))))) to install any program, which is probably as aids-ridden as those AUR packages in OPs pic related.
>>105961325
Its harder to catch internet aids by downloading software from developers website than using repos maintained by literallywho chink apt group.
Replies: >>105961801 >>105961932
Anonymous
7/20/2025, 1:39:35 AM No.105961731
>>105961630
The malware wasn't in updates.
"firefox-patch-bin" isn't an update of firefox, it's some random guy's own version that hopefully nobody was stupid enough to install.
It's like downloading Firefox from firefox.not.a.scam.saaar.in instead of from firefox.com
Anonymous
7/20/2025, 1:41:57 AM No.105961752
>>105961690
ok, i guess i dont know enough about arch btw
Anonymous
7/20/2025, 1:49:10 AM No.105961793
janny_clitty_leak
janny_clitty_leak
md5: 5570d24fdbb228d7141e4f7ebf4978ce๐Ÿ”
Whats the matter, janny? Having a melty from your GNU + axewound? Did my post hurt your tranny feelings? Too bad I have fuck ton of IPs to waste.
Anonymous
7/20/2025, 1:50:10 AM No.105961801
>>105961730
>You can also install software from an offline installer that has all its dependencies included
You can do it on Linux too. I can't think of any incident where a package maintainer of any distro spread malware. The xz incident for example wasn't any package maintainer, but the developer of the software.

As for trusting the package maintainer, there is the whole idea of reproducible builds.
Replies: >>105961855
Anonymous
7/20/2025, 1:51:24 AM No.105961813
Rare instance of the flamewar rule actually being enforced. Nice.
Replies: >>105961847 >>105961855
Anonymous
7/20/2025, 1:54:06 AM No.105961834
1745739424425074
1745739424425074
md5: fe05cf7abbebcec6a431a581432945d1๐Ÿ”
remember when mint was pawned too? fucking kek
Replies: >>105962001
Anonymous
7/20/2025, 1:55:07 AM No.105961847
>>105961813
the thread is still up, though
Replies: >>105961906
Anonymous
7/20/2025, 1:55:43 AM No.105961854
Screenshot 2025-07-20 at 00-55-25 AUR (en) - librewolf-bin
What are we supposed to be mad about, Librewolfbros?
Anonymous
7/20/2025, 1:55:52 AM No.105961855
>>105961801
>You can do it on Linux too.
with 5 programs in total that actually supply you with working tarballs. Want to use package manager? Ooops, you have to bend the knee to the cloud jew. Using flatpaks instead? Ooops, seems like you need to bend the knee to cloud jew as well. Maybe you downloaded .deb / .rpm file offline? Well, its 20 dependencies need internet connection, you know the drill. Meanwhile on old windows the vast majority of software comes with all the dependencies preinstalled. Big dependencies like .net framework or vc++ have offline installers as well.
>The xz incident for example wasn't any package maintainer, but the developer of the software.
>As for trusting the package maintainer, there is the whole idea of reproducible builds.
cope
>>105961813
>actually being enforced
tranny-janny cant do shit since I am literally evading right now. Get fucked.
Replies: >>105961969
Anonymous
7/20/2025, 1:56:58 AM No.105961863
07.20.25 | 12:56:25
07.20.25 | 12:56:25
md5: a0d82d701ddbc72cb8ab35dc4fac4d22๐Ÿ”
Anonymous
7/20/2025, 2:02:47 AM No.105961906
>>105961847
This thread is neutrally and politely talking about tech without trying to start flamewars, albeit
Anonymous
7/20/2025, 2:06:37 AM No.105961932
>>105961730
your entire operating system has security vulnerabilities that are never fixed, retard
>ISPs router
dumb argument
>offline installer
even dumber argument
those offline installers are from shady websites, cracked, patched and shit
Replies: >>105962091
Anonymous
7/20/2025, 2:10:20 AM No.105961967
>arch users pretending they don't blindly install aur packages and most definitely do read every pkgbuild
Replies: >>105963007
Anonymous
7/20/2025, 2:10:20 AM No.105961969
>>105961855
>Get fucked.
impotent
Anonymous
7/20/2025, 2:15:02 AM No.105962001
>>105961834
That was way worse in comparison. Malware got distributed as the official iso. AUR incident is just "malware got uploaded to the user repository known for having malware uploaded to it and warns about potential malware, again"
Anonymous
7/20/2025, 2:26:36 AM No.105962091
>>105961932
>your entire operating system has security vulnerabilities that are never fixed, retard
couldn't care less as noone cant take advantage of them, tranny
>dumb argument
learn the basics of networking, tranny.
>even dumber argument
those offline installers are from shady websites, cracked, patched and shit
And they still work in better and more independent way than any linux software, you terminally online tranny.
Anonymous
7/20/2025, 3:17:40 AM No.105962545
>>105960259 (OP)
>>105960259 (OP)
>concerned about โ€œremote access Trojanโ€
>ignore systemd
Anonymous
7/20/2025, 4:00:30 AM No.105962844
Reminder

https://www.youtube.com/watch?v=BqMf6XFacR8
Anonymous
7/20/2025, 4:12:50 AM No.105962938
>>105960339
/this - Is the gotcha that arch doesn't secure their official repos?
Anonymous
7/20/2025, 4:21:19 AM No.105963007
>>105961967
>arch users pretending they don't blindly install aur packages and most definitely do read every pkgbuild
Yes, I do, actually. It takes all of two seconds to breeze through a PKGBUILD and make sure it isn't doing anything fucky.
Anonymous
7/20/2025, 4:23:04 AM No.105963020
>>105960259 (OP)
>AUR
>firefox-*patch*-(((bin))l
I sleep
Anonymous
7/20/2025, 4:23:36 AM No.105963025
>>105960259 (OP)
>what's stopping people from replacing packages with straight malware?
>popularity
>how about replacing source code with malware?
>popularity
what a fucking joke ecosystem
Anonymous
7/20/2025, 4:24:22 AM No.105963034
>>105961603
No it didn't "infect" Arch or anyone besides Debian and Fedora.
The build system only injected malicious code in the binary if you were building on one of those systems.
You can diffoscope the Arch tarball build vs git build if you want to see for yourself.
Of course the malicious files were static in the git repo, and there was other fucky stuff in the git repo before the cleanup.
But the "infection" of the binary only triggered via tarball build on Debian or Fedora.
Replies: >>105964456
Anonymous
7/20/2025, 4:27:37 AM No.105963056
>>105960342
>Backup
>save the infection to reinstall later on your new ``trusted'' system
lol
It is called Flatten & rebuild. Burn it all and begin anew.
Replies: >>105963528
Anonymous
7/20/2025, 4:31:28 AM No.105963087
How did the malware work? Did it just create a service or what? I wonder if using Artix would have prevented it
Anonymous
7/20/2025, 4:42:19 AM No.105963174
>>105961643
The flaw with Arch's system is that the voting is weighted towards the voters real life weight.
It creates an imbalance.
Anonymous
7/20/2025, 4:43:53 AM No.105963188
>>105960259 (OP)
gentoochuds stay winning
Anonymous
7/20/2025, 5:07:41 AM No.105963360
>>105960259 (OP)

op is a moron
Anonymous
7/20/2025, 5:17:24 AM No.105963441
>>105960259 (OP)
>trannyfox
>trannywolf
>tranny loonix
Tranny ware
Anonymous
7/20/2025, 5:19:52 AM No.105963460
>>105960310
rm -rf /
Anonymous
7/20/2025, 5:20:40 AM No.105963466
Even bigger nothingburger than xz
xz:
>potential to give remote access to millions of computers
>3 years in the making
>caught before it reached stable releases
>only worked in Debian and Fedora

AUR Malware:
>already expected, community repositories are inherently unsafe, same shit as Flathub or Snapstore
>only affects Arch... users who download random packages without knowing what they are from the AUR
>almost immediately removed when detected
>no official repos affected
>no popular packages affected
>build systems not disturbed
>maintainers not disturbed
If you care about this other than "Shouldn't Arch have a little more security in the AUR with how much it's grown?" then you are a complete retard.
Anonymous
7/20/2025, 5:27:06 AM No.105963510
ITT archtroons on damage control again
Anonymous
7/20/2025, 5:29:20 AM No.105963528
>>105963056
You can probably salvage your files with clamav on a live USB. Though obviously you should have a preexisting backup not on-disc anyway.
Anonymous
7/20/2025, 5:32:27 AM No.105963550
>>105960259 (OP)
Patches and fixes for what though?
AUR is limewire all over.
Replies: >>105964364
Anonymous
7/20/2025, 7:31:38 AM No.105964302
>>105960259 (OP)
>The absolute fucking state of Linux
huh? those are AUR packages, i.e. submitted by randoms. would you laugh at windows if someone downloaded an .exe from a 4chan user?
Anonymous
7/20/2025, 7:33:28 AM No.105964307
Do people even use these packages?
Replies: >>105964336
Anonymous
7/20/2025, 7:46:19 AM No.105964336
>>105964307
>check first one
>"first submitted <4 days ago>"
>2 votes
unlikely anybody used it
Anonymous
7/20/2025, 7:47:24 AM No.105964341
Retina Macbook Pros doesn't have this problem
Anonymous
7/20/2025, 7:52:04 AM No.105964350
linux must be pretty good if this is the best people can do to discredit it
Anonymous
7/20/2025, 7:53:29 AM No.105964356
>>105960310
rollback to the btrfs snapshot that was made automatically by the pacman hook to just before you installed it
Anonymous
7/20/2025, 7:54:43 AM No.105964364
>>105963550
likely nothing at all, and are just bait named to get someone to mistakingly install it instead of another legit package
Anonymous
7/20/2025, 8:05:37 AM No.105964414
Why even host these package recipes on official infra if you're not going to at least have someone take a look at the source URIs for a hot minute?
Anonymous
7/20/2025, 8:17:15 AM No.105964455
file
file
md5: 33d2e4852f5b287d7e62a126f29ed07c๐Ÿ”
>librewolf-fix-bin
Wew, dodged the bullet.
Anonymous
7/20/2025, 8:17:36 AM No.105964456
>>105963034
It affected TESTING repos of Debian Unstable and Fedora rawhide, didn't get into stable.
To be fair, the xz bug was something that wasn't detected by normal testing. Arch nature allows packages to be removed asap while Debian and Fedora have to test package replacements and usually takes hours after malware detection.
Anonymous
7/20/2025, 8:21:45 AM No.105964479
>>105960451
People using auch and the aur are extra retarded
Anonymous
7/20/2025, 8:23:04 AM No.105964487
>>105960259 (OP)
>installing unofficial versions of a web browser that contained to be fixed when there is literally no issue that needs to be fixed with any of those browsers.
I mean, what did you expect?
Anonymous
7/20/2025, 8:40:48 AM No.105964570
>>105961579
It was a state actor so he only wanted to infect useful systems used by organisations. Not some system used by some trannie neets full of child porn.
Anonymous
7/20/2025, 8:55:01 AM No.105964644
>>105961282
Exactly. More users there are, more enshittification ensue. The few benevolents will not be able to handle the mass.
Anonymous
7/20/2025, 9:00:45 AM No.105964674
>>105960451
>However, if Linux popularity increases, then AUR will become more vulnerable, so Archtroons will need to come up with some ideas to secure AUR
We already did: voting system
Anonymous
7/20/2025, 9:04:33 AM No.105964696
>>105960259 (OP)
Why would you install firefox from the AUR in the first place? Retardation?
Replies: >>105965622
Anonymous
7/20/2025, 11:53:20 AM No.105965622
>>105964696
firefox from the official arch repository is customized. same for chromium which has an archlinux google api key allowing google to track everything from arch users. you are so naive.
Anonymous
7/20/2025, 1:21:31 PM No.105966197
>>105960259 (OP)
It was some randomโ€™s spin-off patches.
That does give me an idea though.
>Upload malware to AUR on an alt.
>Self report to gain recognition as a malware-buster.
>????
>Profit
Seems like it would be a really easy grift.
Anonymous
7/20/2025, 1:47:17 PM No.105966419
>>105960259 (OP)
Obviously done by a chrome user. (witness me)
Anonymous
7/20/2025, 4:45:56 PM No.105967807
>>105960259 (OP)
>AUR
next your gonna tell me about that "gold" chain you bought from a gypsy?
Anonymous
7/20/2025, 4:49:07 PM No.105967836
I'm going to repost this in EVERY. tranny gayming thread on /v/
You can't stop me
You can mass report me
But I WILL shit on your troonix gayming thread on /v/
Replies: >>105968231
Anonymous
7/20/2025, 5:30:21 PM No.105968231
>>105967836
sir this is /g/