Robin Candau is probably telling the truth when he claims that the Arch Team is "not lacking ideas".
The attacks are a real pain, but it seems the Arch Team is working on it. I don't think it should go so far as to make the AUR as reliable as official repositories, but right now I get the impression that's what's expected. If such large-scale attacks can be reduced in the future, everything else can stay the same: "Welcome to the AUR! Please read the AUR User Guidelines for more information and the AUR Submission Guidelines if you want to contribute a PKGBUILD. Contributed PKGBUILDs must conform to the Arch Packaging Standards otherwise they will be deleted! Remember to vote for your favourite packages! Some packages may be provided as binaries in [extra]. DISCLAIMER: AUR packages are user produced content. Any use of the provided files is at your own risk." - https://aur.archlinux.org/
