Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Arch developers can code "pacman -U" such that it performs a VirusTotal scan before installation for each package.

AFAIK, VirusTotal only flags known malware/viruses, any new/"looks-to-be-new" stuff wouldn't be flagged until they've picked it up, and once someone would have picked it up, it should be removed from the AUR anyways. So you'd have at least one user (most likely more) getting infected first, and once detected more users wouldn't be able to install it regardless.



> So you'd have at least one user (most likely more) getting infected first, and once detected more users wouldn't be able to install it regardless.

This is where your and my intentions differ. I don't want the average Arch user to be infected when it can be prevented because the malware is known about.


> I don't want the average Arch user to be infected when it can be prevented because the malware is known about.

Me neither, my argument would be that VirusTotal won't stop the initial users from getting infected, so not good enough in my mind.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: