Request #87172 has been Rejected by Auerhuhn [1]:

Hi Emiliano,

thanks for your request and taking your time to address this issue.
Like many other users who have posted on aur-general lately, you seem
to care about trust and that AUR users are safe. I find that
commendable. So, thank you for being a good upstream maintainer and
AUR citizen.

However, I regret to say that I have decided to close your deletion
request.

I’m personally convinced that trust chains are a helpful instrument.
The AUR’s trust model, however, doesn’t involve the kind of chain of
trust you seem to be aiming for. We’ve had an incident last week where
an upstream maintainer was also the PKGBUILD author, and their
upstream
project source included malicious code. We were extremely lucky to
have
AUR users flag the PKGBUILD quickly, so not much damage was done. But
the plot twist that came up during the post mortem when another user
looked at the IOCs [0] is that the upstream maintainer was most likely
**completely benign** though reckless, and they got their dev machine
infected by a known nasty worm which had sneakily amended upstream
Git commits with a dropper that allowed the worm to spread, and snuck
it onto upstream via force push. Their security hygiene was poor but
that’s not the point. The point is that from an AUR user’s point of
view, there’s no difference in whether a third party packager owns a
PKGBUILD or the upstream author itself. The AUR user may trust any of
them, or both, but it’s ultimately not helpful, they have to audit
what
they’re installing.

One chain of trust that *may* actually emerge specifically in the case
of Trustsight is that once a user has bootstrapped Trustsight, they’re
always free to use it to audit its own successor. So the problem
you’re
proposing (“disrupting the trust chain”) is actually just a one-time
concern. I think you’ll agree that this fact weakens your case
somewhat.

There are two things you can do that I’d like you to be aware of: 1.
you’re free to contact the PKGBUILD owner and ask them to add you as a
co-maintainer; 2. regardless of whether they’ll accept your request,
you
can subscribe to the PKGBUILD, which sends you emails about future
uploads, and you’re free to have that email notification trigger your
tool to re-assess the PKGBUILD safety/security if you want, and in
case
it finds the PKGBUILD has gone rogue, flag it on the list and we’ll
act
(hopefully) within minutes. Even though I think it’s cool that you
seem
to care deeply about AUR safety, the AUR deliberately allows third
parties to own a PKGBUILD, even if the upstream author objects to
that,
or if they object to the fact that the PKGBUILD is on the AUR in the
first place.

I trust that to a degree, you’ll understand that I’m going to close
your
request.
Thanks again for your work and for continuing to be a vigilant AUR
citizen.


Regards
Claudia


[0]: https://lists.archlinux.org/archives/list/aur-
[email protected]/message/ST4RIYSBS5IAIZ4PVNGW2LQEGBUL7I2L/

[1] https://aur.archlinux.org/account/Auerhuhn/

Reply via email to