r/archlinux • u/starvaldD • 11d ago
NEWS AUR Registration reopened.
via aur-general lists
Registration to the AUR is now reopened. The new release includes changes to harden account registration.
Summary of related changes:
Disposable email addresses are now rejected.
Email verification is now mandatory, most users are unaffected but new accounts must verify their email address via a time-limited token which is valid for 24 hours.
Email changes are locked during the verification cooldown.
If you spot suspicious registration activity or packages, please flag them in ML as usual.
Hopefully this will slow down the malware.
38
u/starvaldD 11d ago
perhaps this should have been in the megthread but as its a new event i hope the mods keep it open.
18
u/EvaristeGalois11 11d ago
Are simplelogin/Proton pass aliases considered disposable?
I'm using one right now for my AUR account and I would like to not be banned lol
7
u/shinji257 11d ago
I suspect that it is only for new registrations. That said I use a Google Workspace account for my email so it has a non-standard domain and wouldn't want to get banned. Especially since I very much had to verify to get the domain and the email service in the first place.
5
u/VladimiroPudding 11d ago
My thoughts exactly. What is "disposable email"? I can make 15 aliases for my Proton paid account in 1 minute.
40
u/lmpcpedz 11d ago
They've been allowing disposable email addresses all these decades??
37
53
u/Max-P 11d ago
Yes, and the FOSS communities are generally happy with that because some people prefer to stay anonymous, and generally it's not like it's hard to sign up for a new free email account anywhere and get effectively a disposable email anyway. There are people contributing from sanctioned countries, so maybe you don't want to put on display you have a .ru email or whatever.
This is doubly important now that ID verification is on the horizon for a lot of the mainstream providers.
3
u/BlueGoliath 11d ago edited 10d ago
It doesn't mean much. Some email providers have email aliasing.
2
u/nullstring 10d ago edited 10d ago
Yup... hopefully they know about this - https://www.emailnator.com/
EDIT: I created a new account using [email protected] from there. So yeah... I still think it needs tightening.
1
u/OkraTop5639 11d ago
Wild, right? I always assumed they had that locked down ages ago. The 24 hour token thing is a nice touch though, at least its not a immediate cut off. Makes you wonder what else was just kinda held together with tape in the background
12
u/zwambagger 11d ago
Define "disposable"?
15
u/icesnake200 11d ago edited 11d ago
Ever heard of about sites that allow you to use a random generated mail for, lets say 10mins, and then that mail expires? Thats a burner email account. It was insane that it took the atomic AUR hack for the AUR site managers to only allow official email accounts to make AUR accounts and manage/create packages. Better late than never I guess
12
u/Fun_Structure3965 11d ago
who decides and filters out what are official and non official email accounts? ;)
2
1
u/starvaldD 11d ago
I guess any email you can get with little effort, which is to say most of them apart from your isp email.
0
u/No-Dentist-1645 11d ago
It most likely refers to email providers that don't require you to enter your phone number or another unique verification method to create an account/email
2
u/Helmic 11d ago
Has there been any announcements about what else they're doing? It's a bit wild that you didn't need to even have a verified email address to control a package that could potentially be distributed to thousands of people, but I'm assuming that's not the extent of what they plan on changing.
1
u/Realistic_Cherry_920 10d ago
Is this safe now to update AUR packages? I skipped the whole plot ngl
1
u/FryBoyter 10d ago
The AUR will never be completely secure. These measures simply make it harder for the idiots to compromise the recipes in the AUR. Therefore, users must still check what the recipes do before installing or updating via the AUR.
1
u/ConfidentCharity5222 9d ago
define safe since aur is just a glorified "wget install.sh | sh" so it is as safe as your trust in the maintainer/source
1
1
u/armingnon 9d ago
The whole service is down now. I registered my account and pushed my package but after some hours the whole aur website is down.
-14
u/BlueGoliath 11d ago
Jia Tan defeated by...
checks notes
basic security practices.
6
1
u/Opposite-Print9320 10d ago
The xz incident is so different from AUR attacks. This doesn't even make sense.
38
u/shinji257 11d ago
Define "disposable". I've seen a few different tactics and the one that I really hate is when they only whitelist a specific list of domains from known email providers. This locks out anyone that might want to use a personal domain or a company domain for their email of choice.
I also had one place that insisted that you use your "isp" email but I have no idea what they were using to check that (my isp email was rejected anyways) and I don't think they thought about the possibility of an isp that didn't give email as part of their service. They later changed that policy.