• Sonalder@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    edit-2
    9 hours ago

    AUR has never been a good idea. I don’t use it and this news proved me right.

    Does that mean a distro official package manager would be immune to infections? Of course not, but they do offer a more secure distribution system and build greater trust. Minimizing the chance of malware being spread through their means.

    Edit: If you have the knowledge and time to inspect the AUR packages you install, AUR might be good for you. I have none of these, that’s why I stick to my official distro packages (and sometimes also some flatpak but from official sources)

    • HaraldvonBlauzahn@feddit.org
      link
      fedilink
      arrow-up
      3
      ·
      9 hours ago

      Minimizing the chance of malware being spread through their means.

      Right. And there is another angle to that: It is far easier to turn an ecosystem into a breeding ground for malware, than to get rid of it again. Once a system has a reputation to be easily hackable, it attracts malware like spoiled meat attracts flies.