In terms of ideas floating around, this seems approachable. Of course there's the initial setup lift, but this is something I couls see myself volunteering on a few times a month to get through a few packages. -- Secured with Tuta Mail: https://tuta.com/free-email
Aug 9, 2026, 15:52 by [email protected]: > Hi guys, > > I have to confess that I haven't read through all the discussions about the > current malware problem hitting the AUR, so please let me know and/or ignore > the proposal if it has been already put forward. > > Analysing the situation, there are many packages in the AUR, too many for the > TUs to constantly check all of them. But there are also many users with > variable expertise who could contribute to checking the packages. So, maybe > it is possible to crowdsource the security inspection to the users? The issue > is just, how to know which users to trust, and how to collect the results and > make them available centrally. > > Maybe you have heard of the project Galaxy Zoo (> > https://www.zooniverse.org/projects/zookeeper/galaxy-zoo> ) which lets users > classify astronomical images, for example by the James Webb Space Telescope. > The main idea is: A single user might make mistakes in the classification, > but if you let many users do the classification, you will get quite reliable > results. > > I'm imagining a web interface which presents a registered AUR user with a > random PKGBUILD and asks them to check it for security issues. The users just > chooses between "safe" and "compromised" (a free text field could also be > useful though, for explaining what exactly is bad in the latter case). > PKGBUILDs reported as compromised by at least one user (or a higher number, > if the number of false positives is otherwise too high) are reported to the > TUs. > > A user's reliability could be estimated as follows: If a TU marks a PKGBUILD > as "safe", all users who also marked it as "safe" get an increase in their > reliability score, same with "compromised". If a user was wrong as compared > to a TU, their reliability score gets decreased. The reliability score could > then be used to weight the users' classifications of a given PKGBUILD, but > also adds an element of gamification to the process, thus increasing > participation. > > For each PKGBUILD the weighted average of the crowdsourced security > evaluation and also the number of "safe" and "compromised" votes could be > shown, such that users that want to use a PKGBUILD already are presented with > the community's estimate. > > Obviously, such a system can be abused by malicious actors which would mark > compromised packages as safe. Also, inexperienced users could distort the > average by missing something. But I'd suspect that the number of trustworthy > and at the same time experienced users is quite high, and thanks to the > reliability score the malicious or unintentionally wrong votes will quickly > loose their weight in the weighted average. > > What do you think? > > Regards, > Michael >
