logoalt Hacker News

WD-42today at 4:53 PM9 repliesview on HN

I’ve been using arch for nearly 2 decades at this point. It’s amazing that the AUR went this long without any serious attacks.

It’s a different world now. I can’t help but feel there used to be honor among hackers. You didn’t go after your own. What kind of jerk would attack Arch Linux?


Replies

sp0rktoday at 5:04 PM

> I can’t help but feel there used to be honor among hackers. You didn’t go after your own. What kind of jerk would attack Arch Linux?

This has absolutely not ever been the case.

show 4 replies
static_motiontoday at 7:47 PM

The reason is popularity. SteamOS is Arch-based and in the hands of a ton of people who aren't necessarily that technical. CachyOS and EndeavourOS have become very popular with the increasing adoption of desktop Linux. The AUR thus becomes an enticing attack surface.

al_borlandtoday at 6:37 PM

> I can’t help but feel there used to be honor among hackers.

My assumption is these aren't so much hackers, as modern day script kiddies armed with LLMs and too much free time.

akerl_today at 6:41 PM

I think you've accidentally lumped together "people who work in tech in / around the field of information security" and "criminals".

There have been a variety of cultural elements to people doing security research / hacking on their own systems / etc.

There has never been "honor" among criminals looking to use technology to steal money or steal things that can be converted to money.

jolmgtoday at 5:11 PM

Arch is simply getting popular enough to be targeted.

show 1 reply
ivanjermakovtoday at 5:34 PM

I'm surprised installing native software is still commonplace. At least in a world of gaming and professional software it's coming from reputable source, but when it comes to PC enthusiasts we've been walking on thin ice for a long time.

I also believe this is the main reason why web took off: effortless distribution and sandboxing.

show 1 reply
cookiengineertoday at 7:25 PM

> What kind of jerk would attack Arch Linux?

The answer is: Russians

Source: I'm the guy that built the antimiasma mitigation tool [1] and tracked their malware campaign iterations very closely.

Set LANG to ru_RU.* and the malware implant stops spreading itself, as with all APT28/29 malware.

[1] https://github.com/cookiengineer/antimiasma

[2] https://cookie.engineer/projects/cyber-defense/antimiasma.ht...

shevy-javatoday at 5:42 PM

Could be AI slop attacks made attacks easier in general. Though, the Arch Linux model was probably never an ideal security model. It seems the easy days of the 1990s are over finally.

charcircuittoday at 4:55 PM

Desktop Linux has always been a house of cards in regards to security. I agree it's amazing that it went on for so long, but this was inevitable.

show 5 replies