Skip to content

Comment on AURpocalypse now: a look at the recent AUR attacksparent

Comments

Installing anything from the AUR, it has always been the user's responsibility to check whatever they are installing. Has always been this way, and they have always been abundantly clear about this. It is also the reason why archlinux does not provide an official installer like yaourt or yay, they could've even built support for the AUR into pacman.

The AUR is just as safe as installing through a random shell script from github - that is to say: not safe at all.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.