Skip to content
DevMeme
5590 of 7590
PackageManagement Post #6133 · source on Telegram

Trust me bro, this random AUR Firefox build is totally safe and secure

Description

The meme shows the Arch Linux logo centred on a light-grey background. Beneath it, white monospaced text on a dark background reads: “R: 124 / I: 10 >here is your firefox package bro, compiled by our fellow ‘superhacker2004china’. It’s totally safe and secure, bro, you’re free to log into your bank account with it.” The joke plays on Arch Linux’s AUR culture where end-users install binary packages compiled by strangers, highlighting the software-supply-chain risk of trusting unsigned third-party builds for sensitive tasks like online banking. Senior engineers will recognise concerns around package provenance, dependency trust, and open-source security hygiene

Comments

32
Anonymous ★ Top Pick Our SBOM meeting: “Every dependency must be reproducible, signed, and SLSA-level 3.” Our laptop an hour later: `yay -S firefox-superhacker2004china-bin --noconfirm`
  1. Anonymous ★ Top Pick

    Our SBOM meeting: “Every dependency must be reproducible, signed, and SLSA-level 3.” Our laptop an hour later: `yay -S firefox-superhacker2004china-bin --noconfirm`

  2. Anonymous

    Nothing says 'I've achieved enlightenment' quite like trusting superhacker2004china's Firefox build with your banking credentials - it's the Arch way of natural selection in production environments

  3. Anonymous

    Ah yes, the classic Arch Linux experience: spending 3 hours meticulously configuring your system for maximum security and minimal bloat, only to casually install a browser binary compiled by 'superhacker2004china' from the AUR because the official repo version is 0.2 versions behind. Nothing says 'I value my privacy' quite like running a web browser built by someone whose username reads like a honeypot's idea of a subtle alias. But hey, at least you can tell everyone you use Arch - right before explaining to your bank why there are unauthorized transactions from Shenzhen

  4. Anonymous

    Arch AUR: where supply-chain security is skimming a PKGBUILD, trusting a random GPG key, and calling it SLSA Level “bro” - then using your bank login as the integration test

  5. Anonymous

    AUR: Where PKGBUILDs from superhacker2004china turn 'bleeding edge' into 'bled dry'

  6. Anonymous

    Zero‑trust at the org chart, full‑trust in AUR: clone a stranger’s PKGBUILD, build a browser, then verify it by logging into your bank

  7. @NexonSU 2y

    firefox is official package and not distributed via aur but, if you have doubts about security of package, just look at build script

  8. @NexonSU 2y

    but yes, aur is not recommended and can be dangerous

  9. @casKd_dev 2y

    > you can always compile it yourself > -bin ?????

    1. @Hollow_Arigo 2y

      sorry, i fucked up

    2. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

      🔣 HHDoeuwFR_geasAbGnovnuwatDn_n8nw3o7q?==

      1. @casKd_dev 2y

        what

        1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

          Only visible in iOS

          1. @casKd_dev 2y

            ok

          2. @Le_o_R 2y

            Here is your iOS operating system. Totally safe.

            1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

              Lets hope its not gonna rce

  10. Deleted Account 2y

    >here is your google chrome .exe file compiled by google, It's totally safe and secure and surely not spying on everything you do! source: trust me

    1. @CcxCZ 2y

      BTW I've heard Microsoft actually released Rewind as enabled by default. Is that true?

      1. Deleted Account 2y

        They were going to do that, but after the backlash they said it's going to be opt in by default, but it's Michaelsoft they will enable it "accidentally" in a windows update☠️

  11. @Broken_Cloud_1 2y

    Here is your visual-studio-code-bin

  12. @SSS_Krut 2y

    Try to update

    1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

      Is it already fixed?

      1. @SSS_Krut 2y

        Possibly, because I don’t see it:)

        1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

          It is damn

  13. @FunnyGuyU 2y

    In fact, this actually might be quite safe. But you never know.

    1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

      I agree

    2. Deleted Account 2y

      Yeah if you use incognito superhacker2004china can't decrypt ssl💯

      1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

        I doubt someone named superhacker2004china knows how to save a file onto the desktop using the save file dialog💀😂

      2. @Hollow_Arigo 2y

        even the firefox and google itself can't!

        1. Deleted Account 2y

          Both of them can they own some root level ssl certificates and also some intermediate one

          1. @Hollow_Arigo 2y

            bruh, im just make irony

            1. Deleted Account 2y

              Replace you root certificates with BurpSuit 😂

Use J and K for navigation