Maragato

joined 1 year ago
[–] Maragato@lemmy.world 1 points 3 months ago (1 children)

That is, you admit that most aur users delegate that function to other eyes instead of auditing the external code they are installing. A user repository outside of the official distribution repository is not a secure means of installing packages on the system, which may have root access to the system and the source code may change with each package update. Do you think that every time there is an update to a package that is not widely used, others will audit the source code for you? For that reason I stopped using Aur and by extension Arch, as their software catalog outside of aur is small.

[–] Maragato@lemmy.world 5 points 3 months ago* (last edited 3 months ago) (9 children)

Any major Linux distribution has a system for building packages, it's not something special to Arch. In fact, Arch's great advantage of the aur repository actually becomes a disadvantage by introducing instability and insecurity into your system when you add programs from that repository. It's amazing that people criticize Windows security with .exe's and then install packages from external repositories with the security of "trust in the repository". How can you trust code with root access to the system just because it's in the aur repository? That's the main question I would ask Arch users.

[–] Maragato@lemmy.world 53 points 3 months ago (6 children)

Most of the time it is achieved with the phrase: "I use Arch, btw". 😉

 

I have always been afraid to install Arch because they tell you it is difficult to install and unstable. I want a simple system following the KISS philosophy and install only what I need, which is little. I don't need anything from the aur repository, for now. Just a year ago I installed Arch and there it is, no problems and doing every day pacman -Syu. It has been a real discovery for me, it's the only distribution I've had this last year that hasn't crashed. I didn't expect it, but Arch has made me change my opinion and pay less attention to the opinions of "youtubers" and more to my own experience. In your experience of use, has Arch been stable in its operation?

[–] Maragato@lemmy.world 2 points 5 months ago

If you want full system control and a rolling distribution with a good security setup, stay with openSUSE Tumbleweed. Immutable distributions like SilverBlue, Aeon,...are not recommended for everyone, only for those who don't want to administer their system and who have good hardware and a good internet connection.