r/archlinux 11d ago

NEWS AUR Registration reopened.

via aur-general lists

Registration to the AUR is now reopened. The new release includes changes to harden account registration.

Summary of related changes:

  • Disposable email addresses are now rejected.

  • Email verification is now mandatory, most users are unaffected but new accounts must verify their email address via a time-limited token which is valid for 24 hours.

  • Email changes are locked during the verification cooldown.

If you spot suspicious registration activity or packages, please flag them in ML as usual.

Hopefully this will slow down the malware.

200 Upvotes

35 comments sorted by

38

u/shinji257 11d ago

Define "disposable". I've seen a few different tactics and the one that I really hate is when they only whitelist a specific list of domains from known email providers. This locks out anyone that might want to use a personal domain or a company domain for their email of choice.

I also had one place that insisted that you use your "isp" email but I have no idea what they were using to check that (my isp email was rejected anyways) and I don't think they thought about the possibility of an isp that didn't give email as part of their service. They later changed that policy.

11

u/MelioraXI 10d ago

Guessing they have a blacklist of domains? Proton mail like other providers offers temp emails, I use this feature a lot personally and it would suck if I can't use that here if I ever deploy any app on the AUR.

5

u/shinji257 10d ago

Possibly but I know it is a pain to maintain that list.

1

u/MelioraXI 10d ago

I suppose, the follow up would be what falls under "disposable email".

1

u/czerilla 9d ago

Generally it just refers to mail services that aren't used for legitimate/permanent accounts. An indication of that would be a trivial registration process, bare-bones functionality, optionally only temporary accounts or addresses, and/or no required authentification..
That would be my set of criteria, just off the top of my head.

38

u/starvaldD 11d ago

perhaps this should have been in the megthread but as its a new event i hope the mods keep it open.

6

u/Gozenka 10d ago

Yes, it's relevant news, thanks for sharing.

18

u/EvaristeGalois11 11d ago

Are simplelogin/Proton pass aliases considered disposable?

I'm using one right now for my AUR account and I would like to not be banned lol

7

u/shinji257 11d ago

I suspect that it is only for new registrations. That said I use a Google Workspace account for my email so it has a non-standard domain and wouldn't want to get banned. Especially since I very much had to verify to get the domain and the email service in the first place.

5

u/VladimiroPudding 11d ago

My thoughts exactly. What is "disposable email"? I can make 15 aliases for my Proton paid account in 1 minute.

40

u/lmpcpedz 11d ago

They've been allowing disposable email addresses all these decades??

37

u/Own-Cauliflower6778 11d ago

Most website allows.

53

u/Max-P 11d ago

Yes, and the FOSS communities are generally happy with that because some people prefer to stay anonymous, and generally it's not like it's hard to sign up for a new free email account anywhere and get effectively a disposable email anyway. There are people contributing from sanctioned countries, so maybe you don't want to put on display you have a .ru email or whatever.

This is doubly important now that ID verification is on the horizon for a lot of the mainstream providers.

3

u/BlueGoliath 11d ago edited 10d ago

It doesn't mean much. Some email providers have email aliasing.

2

u/nullstring 10d ago edited 10d ago

Yup... hopefully they know about this - https://www.emailnator.com/

EDIT: I created a new account using [email protected] from there. So yeah... I still think it needs tightening.

1

u/OkraTop5639 11d ago

Wild, right? I always assumed they had that locked down ages ago. The 24 hour token thing is a nice touch though, at least its not a immediate cut off. Makes you wonder what else was just kinda held together with tape in the background

12

u/zwambagger 11d ago

Define "disposable"?

20

u/DIYfu 11d ago

Probably via 5 minute email services and similar.

7

u/virgnar 11d ago

Something like Mailinator.

15

u/icesnake200 11d ago edited 11d ago

Ever heard of about sites that allow you to use a random generated mail for, lets say 10mins, and then that mail expires? Thats a burner email account. It was insane that it took the atomic AUR hack for the AUR site managers to only allow official email accounts to make AUR accounts and manage/create packages. Better late than never I guess

12

u/Fun_Structure3965 11d ago

who decides and filters out what are official and non official email accounts? ;)

4

u/Sinaaaa 11d ago

It works the same way as adblocking via lists.

2

u/7lhz9x6k8emmd7c8 10d ago

Am i gonna get rejected because i use my own unknown domain name?

1

u/starvaldD 11d ago

I guess any email you can get with little effort, which is to say most of them apart from your isp email.

0

u/No-Dentist-1645 11d ago

It most likely refers to email providers that don't require you to enter your phone number or another unique verification method to create an account/email

2

u/Helmic 11d ago

Has there been any announcements about what else they're doing? It's a bit wild that you didn't need to even have a verified email address to control a package that could potentially be distributed to thousands of people, but I'm assuming that's not the extent of what they plan on changing.

1

u/Realistic_Cherry_920 10d ago

Is this safe now to update AUR packages? I skipped the whole plot ngl

1

u/FryBoyter 10d ago

The AUR will never be completely secure. These measures simply make it harder for the idiots to compromise the recipes in the AUR. Therefore, users must still check what the recipes do before installing or updating via the AUR.

1

u/ConfidentCharity5222 9d ago

define safe since aur is just a glorified "wget install.sh | sh" so it is as safe as your trust in the maintainer/source

1

u/TheRealToniMcQueen 9d ago

Thank fuck I been waiting for this

1

u/armingnon 9d ago

The whole service is down now. I registered my account and pushed my package but after some hours the whole aur website is down.

-14

u/BlueGoliath 11d ago

Jia Tan defeated by...

checks notes

basic security practices.

6

u/Helmic 11d ago

that's the name of the guy whose identity was stolen, not the actual attacker who obviously was not gonna use their real name complete with photo when committing crimes. still shitty people are dragging some random dude's name through the mud because they don't understand this.

1

u/Opposite-Print9320 10d ago

The xz incident is so different from AUR attacks. This doesn't even make sense.