In terms of ideas floating around, this seems approachable. Of course there's 
the initial setup lift, but this is something I couls see myself volunteering 
on a few times a month to get through a few packages.
-- 
 Secured with Tuta Mail: 
 https://tuta.com/free-email


Aug 9, 2026, 15:52 by [email protected]:

> Hi guys,
>
> I have to confess that I haven't read through all the discussions about the 
> current malware problem hitting the AUR, so please let me know and/or ignore 
> the proposal if it has been already put forward.
>
> Analysing the situation, there are many packages in the AUR, too many for the 
> TUs to constantly check all of them. But there are also many users with 
> variable expertise who could contribute to checking the packages. So, maybe 
> it is possible to crowdsource the security inspection to the users? The issue 
> is just, how to know which users to trust, and how to collect the results and 
> make them available centrally.
>
> Maybe you have heard of the project Galaxy Zoo (> 
> https://www.zooniverse.org/projects/zookeeper/galaxy-zoo> ) which lets users 
> classify astronomical images, for example by the James Webb Space Telescope. 
> The main idea is: A single user might make mistakes in the classification, 
> but if you let many users do the classification, you will get quite reliable 
> results.
>
> I'm imagining a web interface which presents a registered AUR user with a 
> random PKGBUILD and asks them to check it for security issues. The users just 
> chooses between "safe" and "compromised" (a free text field could also be 
> useful though, for explaining what exactly is bad in the latter case). 
> PKGBUILDs reported as compromised by at least one user (or a higher number, 
> if the number of false positives is otherwise too high) are reported to the 
> TUs.
>
> A user's reliability could be estimated as follows: If a TU marks a PKGBUILD 
> as "safe", all users who also marked it as "safe" get an increase in their 
> reliability score, same with "compromised". If a user was wrong as compared 
> to a TU, their reliability score gets decreased. The reliability score could 
> then be used to weight the users' classifications of a given PKGBUILD, but 
> also adds an element of gamification to the process, thus increasing 
> participation.
>
> For each PKGBUILD the weighted average of the crowdsourced security 
> evaluation and also the number of "safe" and "compromised" votes could be 
> shown, such that users that want to use a PKGBUILD already are presented with 
> the community's estimate.
>
> Obviously, such a system can be abused by malicious actors which would mark 
> compromised packages as safe. Also, inexperienced users could distort the 
> average by missing something.  But I'd suspect that the number of trustworthy 
> and at the same time experienced users is quite high, and thanks to the 
> reliability score the malicious or unintentionally wrong votes will quickly 
> loose their weight in the weighted average.
>
> What do you think?
>
> Regards,
> Michael
>

Reply via email to