logoalt Hacker News

nvme0n1p1today at 5:26 PM2 repliesview on HN

It's funny how these people say Linux security is bad because random people can upload arbitrary files to AUR, but won't say Windows security is bad because random people can upload arbitrary files to Microsoft GitHub.


Replies

davkantoday at 6:24 PM

I think the wrongful notion comes from the fact that the vast majority of Arch users use and speak about AUR as if it were a part of arch proper, only paying lip service to reviewing PKGBUILDS, etc. They wrap the default package manager in one that supports AUR and never touch it directly again. It feels closer to if all of GitHub was available in one click through the Microsoft store or windows update.

And unfortunately that’s how arch is mainly marketed by its users. “Arch has the latest everything, if it’s not in the repos it’s on AUR” is one of the standard selling points.

Of course that speaks to how people use linux insecurely not how Linux is insecure.

show 1 reply
tostitoday at 5:29 PM

MS-Windows gets attacked by the hardware vendors, too.