this post was submitted on 12 Jun 2026
32 points (100.0% liked)

Privacy

49063 readers
1645 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

With all the supply chain attacks in the Linux ecosystem, isn’t the natural solution to move to full application sandboxing?

Flatpacking is great but not all applications support it.

Is it too much of a hassle?

you are viewing a single comment's thread
view the rest of the comments
[–] gary_host_laptop@lemmy.ml 4 points 1 day ago (2 children)

The latest attack on the AUR would be solvable by Nix, in theory, Qubes would still suffer from this, only it's compartmentalized, whereas Nix would be safe from my understanding.

[–] FineCoatMummy@sh.itjust.works 1 points 21 hours ago

The latest attack on the AUR

For anyone else like me who was OOTL, I guess that refers to this...

https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html

If a flagged package ran, treat the host as credential-compromised. Rotate everything the stealer touches: browser sessions, SSH keys, GitHub and npm tokens, Slack, Teams and Discord sessions, Vault tokens, Docker and Podman credentials, and any cloud keys.

If the package ran as root, assume the rootkit is present and reinstall from trusted media. There is no way to trust the system otherwise.

Jeepers!