Isn’t this similar to the reason a lot of people hate snaps? Or am I misunderstanding something? I’m not an Arch user (btw) so I’m not super familiar with AUR.
Besides all the other non infected ways to install the software, there is a way to prevent this: Just read the AUR package before install and don’t trust blindly any new maintainer.
No way to prevent this, says only repo where this regularly happens
Isn’t this similar to the reason a lot of people hate snaps? Or am I misunderstanding something? I’m not an Arch user (btw) so I’m not super familiar with AUR.
You’re right on malware finding its way onto the Snap Store. I find it hilarious to see that the employed tactics are basically identical 😜.
However, FYI, the hate on Snaps is a lot more broad than that.
Not the only repo, see: npm
Npm doesn’t let you easily take over packages you don’t own.
but does let you take over their maintainers’ accounts (through poor security) and easily poison them
Not more easily than anything else.
Besides all the other non infected ways to install the software, there is a way to prevent this: Just read the AUR package before install and don’t trust blindly any new maintainer.
It’s metaphysical approach to security. Enshrined rules that can’t be enforced don’t define user’s behavior.