AUR Registrations Blocked Amid Ongoing Malware Mess
2026-06-18 03:59 UTC
Replies (3)
-
@HaraldvonBlauzahn@feddit.org 2026-06-18 05:36
By the way, secure open trust systems are hard. Around 2000, there was a FOSS web site called kuro5hin.org, which experimented with trust networks. As far as I remember, they did not found a good solution. Wikipedia or stack overflow has the same issues.
-
@placebo@lemmy.zip 2026-06-18 10:11
WTS AUR account, pm for details spoiler jk
-
@Cyber@feddit.uk 2026-06-18 20:29
The problem with these supplychain / wateringhole attacks, is the reputation hit is harder to deal with. If anyone thinks they’ll stop using an AUR package and just install a container, flatpak, etc… they can still be vulnerable, but they’re not using AUR, NPM, etc… I just hope there were enough forensics to make a sensible improvement in security policies & procedures, rather than just guessing what next to do, and then AUR will be stronger for it.