120
submitted 3 days ago by cm0002@lemmy.zip to c/linux@programming.dev

The Arch Linux team has once again been forced to respond to a distributed denial-of-service attack targeting its AUR repository infrastructure. As a result, DDoS protection has been enabled for aur.archlinux.org to help mitigate the ongoing disruption.

While this measure helps keep the AUR website accessible, it has introduced a significant side effect: pushing to the AUR is currently not possible.

you are viewing a single comment's thread
view the rest of the comments
[-] Fecundpossum@lemmy.world 7 points 2 days ago

I wonder if it could be a state actor? I can imagine that the powers that be in MANY countries could be motivated to keep users away from operating system software that isn’t spyware.

[-] Laser@feddit.org 13 points 2 days ago

Then why go against the AUR and not the official mirrors? The former isn't always exactly the epitome of securely packaged trusted applications

[-] Fecundpossum@lemmy.world 5 points 2 days ago

Just spitballing, because honestly the amount of effort that must go into sustaining this attack in the long term just baffles me. Like, why?

[-] Alaknar@sopuli.xyz 1 points 1 day ago

It costs, like $10 to rent a botnet for a couple-hour attack.

this post was submitted on 27 Oct 2025
120 points (100.0% liked)

Linux

9940 readers
404 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 2 years ago
MODERATORS