[SOLVED] Is using AUR safe? (particularly using yaourt )

Hi,
I've been using AUR to compile certain packages, such as psad, lynis, and I often use youart to achieve that.
I recognize there's an array of hashes in PKGBUILD which ensures the integrity of downloaded files,
but I don't see any mechanism to ensure the PKGBUILD is intact during transfer, unlike official packages
which are signed by keys.
So are you guys concerned about PKGBUILD being corrupted or modified, and as a conseqence leading your
system compromised?
Last edited by darrenldl (2013-08-28 09:45:36)

darrenldl wrote:
Hi,
I've been using AUR to compile certain packages, such as psad, lynis, and I often use youart to achieve that.
I recognize there's an array of hashes in PKGBUILD which ensures the integrity of downloaded files,
but I don't see any mechanism to ensure the PKGBUILD is intact during transfer, unlike official packages
which are signed by keys.
So are you guys concerned about PKGBUILD being corrupted or modified, and as a conseqence leading your
system compromised?
If you're really that concerned about PKGBUILDs being intact when you install something from the AUR, you should be checking the PKGBUILD yourself.

Similar Messages

  • Is disc doctor safe to use

    Is Disc Doctor safe to use?

    How to maintain a Mac
    1. Make redundant backups, keeping at least one off site at all times. One backup is not enough. Don’t back up your backups; make them independent of each other. Don’t rely completely on any single backup method, such as Time Machine. If you get an indication that a backup has failed, don't ignore it.
    2. Keep your software up to date. In the Software Update preference pane, you can configure automatic notifications of updates to OS X and other Mac App Store products. Some third-party applications from other sources have a similar feature, if you don’t mind letting them phone home. Otherwise you have to check yourself on a regular basis. This is especially important for complex software that modifies the operating system, such as device drivers. Before installing any Apple update, you must check that all such modifications that you use are compatible.
    3. Don't install crapware, such as “themes,” "haxies," “add-ons,” “toolbars,” “enhancers," “optimizers,” “accelerators,” "boosters," “extenders,” “cleaners,” "doctors," "tune-ups," “defragmenters,” “firewalls,” "barriers," “guardians,” “defenders,” “protectors,” most “plugins,” commercial "virus scanners,” "disk tools," or "utilities." With very few exceptions, this stuff is useless, or worse than useless.
    The more actively promoted the product, the more likely it is to be garbage. The most extreme example is the “MacKeeper” scam.
    As a rule, the only software you should install is that which directly enables you to do the things you use a computer for — such as creating, communicating, and playing — and does not modify the way other software works. Use your computer; don't fuss with it.
    Never install any third-party software unless you know how to uninstall it. Otherwise you may create problems that are very hard to solve.
    The free anti-malware application ClamXav is not crap, and although it’s not routinely needed, it may be useful in some environments, such as a mixed Mac-Windows enterprise network.
    4. Beware of trojans. A trojan is malicious software (“malware”) that the user is duped into installing voluntarily. Such attacks were rare on the Mac platform until sometime in 2011, but are now increasingly common, and increasingly dangerous.
    There is some built-in protection against downloading malware, but you can’t rely on it — the attackers are always at least one day ahead of the defense. You can’t rely on third-party protection either. What you can rely on is common-sense awareness — not paranoia, which only makes you more vulnerable.
    Never install software from an untrustworthy or unknown source. If in doubt, do some research. Any website that prompts you to install a “codec” or “plugin” that comes from the same site, or an unknown site, is untrustworthy. Software with a corporate brand, such as Adobe Flash Player, must be acquired directly from the developer. No intermediary is acceptable, and don’t trust links unless you know how to parse them. Any file that is automatically downloaded from a web page without your having requested it should go straight into the Trash. A website that claims you have a “virus,” or that anything else is wrong with your computer, is rogue.
    In OS X 10.7.5 or later, downloaded applications and Installer packages that have not been digitally signed by a developer registered with Apple are blocked from loading by default. The block can be overridden, but think carefully before you do so.
    Because of recurring security issues in Java, it’s best to disable it in your web browsers, if it’s installed. Few websites have Java content nowadays, so you won’t be missing much. This action is mandatory if you’re running any version of OS X older than 10.6.8 with the latest Java update. Note: Java has nothing to do with JavaScript, despite the similar names. Don't install Java unless you're sure you need it. Most people don't.
    5. Don't fill up your boot volume. A common mistake is adding more and more large files to your home folder until you start to get warnings that you're out of space, which may be followed in short order by a boot failure. This is more prone to happen on the newer Macs that come with an internal SSD instead of the traditional hard drive. The drive can be very nearly full before you become aware of the problem. While it's not true that you should or must keep any particular percentage of space free, you should monitor your storage consumption and make sure you're not in immediate danger of using it up. According to Apple documentation, you need at least 9 GB of free space on the startup volume for normal operation.
    If storage space is running low, use a tool such as the free application OmniDiskSweeper to explore your volume and find out what's taking up the most space. Move rarely-used large files to secondary storage.
    6. Relax, don’t do it. Besides the above, no routine maintenance is necessary or beneficial for the vast majority of users; specifically not “cleaning caches,” “zapping the PRAM,” "resetting the SMC," “rebuilding the directory,” "defragmenting the drive," “running periodic scripts,” “dumping logs,” "deleting temp files," “scanning for viruses,” "purging memory," "checking for bad blocks," "testing the hardware," or “repairing permissions.” Such measures are either completely pointless or are useful only for solving problems, not for prevention.
    The very height of futility is running an expensive third-party application called “Disk Warrior” when nothing is wrong, or even when something is wrong and you have backups, which you must have. Disk Warrior is a data-salvage tool, not a maintenance tool, and you will never need it if your backups are adequate. Don’t waste money on it or anything like it.

  • Errors when using aura

    A lot of times when I use aura (I'd say about 90%) I get an error saying that it couldn't connect to the AUR, because of error '443'. I Googled a bit, and a lot of people who had this issue simply weren't able to connect to the safe https://aur.archlinux.org. That's not the case for me, I can connect fine to that with both firefox and curl.
    What could potentially be causing this issue, and what could be a solution?
    After Googling I tried to set my mtu to 1500 but that hasn't worked either.
    Last edited by Binero (2015-01-06 18:33:20)

    Did you ever resolve this?

  • How do I stop Firefox Start Page using AVG Safe Search?

    When I use the search bar on the Firefox Start Page it uses AVG Safe Search. How can I change this so it uses Google instead?

    See the [[Firefox has just updated tab shows each time you start Firefox]] article for details of how to solve this.

  • Keeping in view sercurity aspects, Is anonymox safe for use ?

    I have concerns regarding security of computer and my personal privacy while using anonymox. I need some rarefactions regarding the same:-
    1-Has the add-ons developed by Mozilla or it is a third party application ?
    2-Is it Safe ?

    Using web based proxies and anonymous proxies in particular is always at your own risk, especially with secure connections you should be careful and never use this when paying and other financial transactions are involved.
    *http://en.wikipedia.org/wiki/Proxy_server

  • ITunes 11.1.3.8, safe to use?

    Is iTunes 11.1.3.8 safe to use with Windows 7 and an iPod Classic?
    I am currently at 11.1.1.1 (and held off on that until they fixed the podcast issues) since I remember there were alot of problems with some devices no longer being recognized to sync, but I think that was mainly Win 8 or 8.1?

    Works fine for me.
    tt2

  • Spilled water on MacBook Air - safe to use after a week?

    Last Friday I spilled a glass of water all over my MacBook Air's keyboard. I jumped up, tipped the laptop over to get as much water off as possible, and dried off the outside. I took it in to Apple immediately and was told it needed so many repairs, that it would cost more than the laptop itself. The guy who looked at my Air was able to turn it on, but the monitor was flickering and had horizontal lines. He took it apart and said the motherboard was fine, but I would need a new logic board, speakers, screen, etc. and said I should be able to get my files off onto an external hard drive. Since it was such a costly repair that I couldn't go for, I didn't get a list of everything that had to be replaced.
    When I got it home, I wasn't able to power it on like he could. I let it sit on my dresser all week, open and upside down, to let it dry and allow any extra water to drip out the front. Tired of looking at it, tonight I decided to try one more time and turn it on, and it did! I was able to email myself some important files that I thought I would never see again, so programs and internet worked. The monitor seemed completely fine, the brightness goes up and down normally, the speakers work, and I didn't notice any problems with the keyboard.
    It seems to be completely fine, but I'm a bit worried about whether or not it's safe to use, and if there's anything I should be looking out for. At the Apple store I was told that it needed so much, but maybe it's fine for now? If I am able to use it, should I be thinking about replacing it anyway? I'll be wanting to use it next fall for school. Sorry for the huge wall of text, I thought it would be best to know as much as possible.
    Thanks.

    That's great news. I'm not a computer guy but I am very experienced in automotive. The way I see it is even when you took it in and they cleaned it there is no way to get all the water out if it's really bad. The water will cause shorts and all kind of thing will malfunction. Now that the water is dried I would take it in and get it retested. You see, the first test they did on it was not accurate because of the water (causing it to short). Now you can get a good test. Who knows, it might be just fine. I remember drying  cars for weeks at a time. One thing to have them look for is any corrosion that might had formed. My guess (only a guess) is that if it's working good now you got really lucky and it will be fine.

  • Boot Camp safe to use with Time Machine?

    Is Boot Camp safe to use with Time Machine? I will be installing Windows on a partition and using an external hard drive to back up. I only want the Mac partition to be backed up, though, since Windows will just be used for applications which I can reinstall if my machine messes up.

    Yes, this is perfectly safe. Time Machine won't backup the Bootcamp Windows partition.

  • [SOLVED] How much space is REALLY used on my HDD?

    Hi there,
    Today I moved my /home/ dir to its own partition, so that my settings are safe from the system.
    I have a question about the used space:
    When I use "df -h" to see how much space is used, this is the output for home:
    /dev/sda2             184G  465M  175G   1% /home
    So 465 MB should be used. When I right click on home and select properties only 243,5 MB are used!?
    I know about the MB/MiB problem... but that would not be that extreme...
    Any ideas?
    greetings, yodo
    Last edited by yodo (2008-05-30 15:06:49)

    yodo wrote:But for what is that reserved space used actually?
    It is used to store information about the filesystem structure. Inodes, Blocks, etc. Have a look at this c't article: http://www.heise.de/open/Das-Dateisyste … l/104859/0 (German article)

  • Is it safe to use an 85watt adapter from a 2006, 17" macbook pro on a late 2011 15" macbook pro?

    Hi. My question is pretty much as the heading says :
    Is it safe to use an 85watt adapter from a 2006, 17" macbook pro on a late 2011 15" macbook pro?
    As far as I can tell from googling and searching around, it does appear that it is safe to do so.
    Specifically this page
    http://support.apple.com/kb/HT2346
    But I just wanted to double-check for confirmation that it is indeed safe to use the adapter from such an old mbook pro in a newer one.
    The wattage is the same.
    I wish to do so as I prefer the T-connector, and my older adapter has a much longer extension cord on it.
    If not I may order another one from ebay.
    Any idea how to check that an adapter from ebay is a true / legitimate / authentic apple adapter?
    Thanks for your help.

    Benway1 wrote:
    Is it safe to use an 85watt adapter from a 2006, 17" macbook pro on a late 2011 15" macbook pro?
    Yes.
    I recommend you buy one directly from Apple. There are many counterfeit power adapters on the market that could damage your MacBook Pro or potentially cause a fire.
    Any idea how to check that an adapter from ebay is a true / legitimate / authentic apple adapter?
    Nearly all of them are, even if the seller insists it is "genuine OEM". Legitimate adapters from eBay are likely to be used, not new. There is nothing wrong with used, as long as you know what you're getting.
    Identifying a counterfeit is possible only through close examination.

  • Is it safe to use the MBP in closed clamshell mode?

    I've connected my MBP to my LCD TV and started to use it as my desktop.
    I'm deactivating the main display of the MBP by putting it into sleep mode and moving my mouse, so it wakes the computer up and shows image only in the TV, keeping the main display turned off.
    I'm constantly monitoring the temperatures of the MBP with iStat Menus. It seems that the temperature is always the same, no matter if the main display lid is open or closed.
    So, based on these 2 articles:
    http://support.apple.com/kb/HT3131
    http://support.apple.com/kb/HT1778
    Is it really safe to use the MBP with the display lid closed?
    If I decide to run a heavy load application (like a game) and the MBP starts to get warm, would it damage the display, because it is too close to the body of the MBP?

    Yes it's perfectly safe and designed to be used that way, 90% of the time this one's used in a similar configuration. The only time the fans come on 100% is when I watch Flash-based items from YouTube or similar. I've never run it for any extended length of time with the fans at maximum I must admit but as long as the air flow is good there shouldn't be any problem.

  • My 17" Macbook Pro battery swelled up and kind of exploded. The apple genuis said it is still safe to use, that doesn't sound right.

    I am just kind of worried that it doesn't even fit. Do I need to kind of pop the expanded portion of the battery to get it to fit back in? The case of the battery has come apart and so to fit it back in I would have to press it back together. The battery is low count and had great capacity when it happened. I don't want to have to buy another one when this one is fairly new.

    ... The apple genuis said it is still safe to use, that doesn't sound right.
    I agree with you, that's not right.
    This may seem to be a little problem - fix it before it becomes a big one.

  • My computer has a virus , is it safe to use iTunes?

    hello
    I want to do backup for my iPhone , but my computer has a virus ,is it safe to use iTunes or not ?

    Yes, it is. For maximum security, uninstall and reinstall iTunes before proceeding, and make a separate backup to the iCloud.
    (125720)

  • Is it safe to use clean my mac download?

    Is it safe to use clean my mac download?

    No. And, it isn't needed. Don't install software like this. It clutters up your computer, can cause slowdowns, and does nothing you can't do better with other software.

  • Using the Safe Mode function on your PlayStation 3?

    i followed the steps it works fine then when i sign in within a afew seconds it cuts off and gets a red flashing light again i dont know what to do :/

     
    RabidWalker wrote:
    Using the Safe Mode function on your PlayStation 3?
    Safe Mode:
    The option to use Safe Mode on the PlayStation 3 was introduced if a problem occurs where it will no longer start up normally.
    To use this feature the console will need to have the System Software update 2.60 (or later).
    When to Use Safe Mode?
    When starting up the PlayStation 3, and the XMB menu no longer appears (you may see a wavy line on the background instead).
    When the PlayStation 3 is started up, nothing appears on screen.
    When the PlayStation 3 is started up and you encounter the following message ‘The Hard disk’s file system is corrupted and will be restored’. When selecting ‘OK’ the system restores and restarts, however the same message appears.
    When the PlayStation 3 is started up and you encounter the following message ‘The Hard disk’s database will be rebuilt’. When selecting ‘OK’ the system begins the operation and then fails (stopping the restoration of the HDD).
    There is an issue after the PlayStation 3 update process is started, or a rebuilding of the database occurs.
    Safe Mode procedure:
    1)    Ensure the PlayStation 3 is in standby mode (where the red light is apparent), and then turn the console off at the mains switch.
    2)    Turn the mains power on, then while in standby touch and hold the power button.
    3)    Keep your finger pressed on the power button (after 5 seconds you will hear a beep).
    4)    After 10 seconds of holding your finger on the power button, you will hear a second beep and the console will shut down (you can remove your finger).
    5)    Touch and hold the power button again.
    6)    Again hold your finger down on the button until you hear another beep after 5 seconds.
    7)    A number of seconds after this you will hear a double beep- you can remove your finger.
    8)    You will be prompted to plug your controller in and press the PS button on your controller. After doing so you will access the Safe Mode menu with a number of options.
    Safe Mode Option Screen:
    Restart System
    Selecting this option will start up the system normally- It will also allow you to exit the Safe Mode Menu.
    Restore Default Settings
    Selecting this option will restore Default settings on your console (when starting the unit you will be prompted to set time, time zone etc). This option will also delete your PlayStation Network account information from the system.
    Your User information will be deleted and restored- the indicator will be an asterix by your username e.g. *RabidWalker.
    When logging into your user you will encounter no issues with disc based games. However when attempting to play PSN downloaded games you may encounter the message:
    ‘To access the system, you must activate the system.
    Go to [PlayStation Network] > [Account Management] to activate this system. (80029514). ’
    Follow the instruction to activate your PlayStation 3 to play downloaded games (if the system is activated, deactivate and reactivate the system)
    Restore File System
    This option will begin a process to repair data on your Hard Disk Drive. Therefore it will check for any corrupted data and try and recover this. It the data cannot be recovered it may be erased to ensure that it does not interfere with the operation of the PlayStation 3.
    Rebuild Database
    If issues continue to persist and you select this option please note that data will be removed during this process.
    The following information will removed:
    -          Messages
    -          Playlists
    -          User changes to Information Screens
    -          User changes to Picture under Photos
    -          Video Thumbnails
    -          Video Playback History
    -          Video Resume Information
    This process may take same time to complete
    Restore PS3 System
    The option to restore PS3 system is the same as the ‘quick format’ option on the XMB menu. It will reformat the HDD, removing all data and restoring the Hard drive to its original state.
    System Update
    Selecting this option will install the PlayStation 3 Update but only if the update is on an external media storage device plugged into the console.
    This option can be used if any issues are encountered with the installation of the System software update.
    If you have any queries regarding this or any other issues please PM me or catch me on Twitter
    @RabidWalker
    Rabid
     

Maybe you are looking for

  • ITunes was not installed correctly Error 7 (Windows error 998)

    HI I had a Trojan and used Malwarebytes to get rid of it and now everything is fine but for some reason everytime I try to open Itunes I get the message ITunes was not installed correctly Error 7 (Windows error 998) I have done various searches on th

  • Bookmark through CLIENT_OLE2

    Hello Seniors/Guru/experts we have custom built oralce application (forms 11g). Here is the detail: we have word template(employee record.dot) store in database through blob. And each template have bookmark .i.e. "Emp name". We are able to call that

  • 27" iMac w/ Radeon 4850 total graphics corruption

    I have a Late 2009 iMac 27" Core i5 with Radeon HD 4850 GPU running 10.6.8.  I came home the other day to find it only showed a black screen after waking from sleep.  After a reboot, it displayed multi-colored vertical stripes immediately after power

  • Migrating from OLAP to relational

    Hi, I am supposed to work on an assignment that needs to migrate the data model from OLAP to relational. Generally the industry is moving the other way, i.e. from Relational to OLAP. In my current assignment I have to re-rengineer an existing reporti

  • Clearing shopping cart upon user logout using Javascript

    Clearing shopping cart upon user  logout using Javascript... How is it done? Anybody got a script handy? Thanks!