On Mon, 2026-08-10 at 22:33 +0200, Cynthia Rey wrote: > But even if we put aside Socket, I found that Ralf's comment[1] on the > "Crowdsourcing security inspection" thread was quite enlightening; I > didn't fully agree with the viewpoint on the first read, but thinking > about it more made me realise that it's a very accurate statement. One > that I believe also applies here.
Hi Cynthia, thank you! Maybe I should have phrased it better. A list moderator asked me off- list not to write anything so "counterproductive" anymore. I’d like to clarify that I’m not opposed to making PKGBUILDs more secure per se, but the last two attacks would have happened even with even more secure PKGBUILDs. Anyone who follows the news has noticed, for several years now, and increasingly in recent months, that, to put it simply, the situation currently looks like this: The world is experiencing attacks on infrastructure in which the payload rarely causes problems (though this may, of course, change in the future), but for now, the malware in the PKGBUILDs (comparable to the explosive payload in a drone at a German airport a few days ago) seems to be less of a problem than the fact that it causes infrastructure to go down temporarily, triggering discussions, disputes, and turf wars, possibly followed by restrictive measures in civil society (and corresponding laws at the government level). That's just my opinion, and I'm going to comply with the "request" to keep quiet now. Regards, Ralf
