Hi Ralf,
in regards to your statements about the AUR attacks I feel like you
might've failed to account for survivorship bias.
We only know about the attacks we have detected. That does not mean we
know that there were no undetected attacks.
The AUR has worked well in the past but I think we are in a position
where we need new principles on how to secure the AUR. The principle of
"many eyes" is not enough to handle larger scale supply chain attacks.
The current AUR downtime and prior lockdowns are evidence of that. The
system is no longer working as intended.
Regarding the gamification: That could easily be deployed as an
additional system users can engage in. You could still manually read
PKGBUILD's on your own and report packages.
I do not see why people would disengage from the AUR because of that
since you could simply ignore it.
Declaring the problem non-existent on subjective reasoning and referring
to it having in the past seems pretty unreasonable to me.
Regards,
Nico
On 10/08/2026 4:00 pm, Ralf Mardorf wrote:
Hi Michael,
so far, the AUR has worked very well based on the principle of "many
eyes". What you're suggesting has been working exactly that way for a
long time, just without nonsense like a score or gamification.
The attacks are annoying, but they were detected immediately upon
occurring. As far as detection goes, there’s absolutely no reason to
change anything. Why drive all those helpful eyes, who’ve noticed this
so far, out of the AUR through scores and gamification?
In any case, I suspect that Arch users are rarely fans of scores and
gamification. But that doesn’t matter, because what works is that the
attacks are detected, the malicious PKGBUILDs were probably not used
very often, if at all.
The real problem is the attacks themselves, not that they might go
undetected.
You’re trying to solve a problem that doesn’t need solving, since it’s
been working reliably for a long time.
Regards,
Ralf