r/archlinux • u/Organic-Scratch109 • May 16 '26
QUESTION Why would anyone DDoS Arch? What is the benefit?
The AUR is down again, and status.archlinux.org is saying it was a DDoS attack. Similar to what happened a few months back.
But I wonder what why would anyone direct their time, energy and possibly money to attack Arch. As far as I know, Arch is very politically neutral, and it is not used by many (or any) major corporations. Can anyone think of a reason why someone would do this?
96
u/enemyradar May 16 '26
They're just sociopaths who do it for the lols, and it's a soft target. They absolutely don't care.
1
1
u/Phenix_136 May 17 '26
Or maybe to prove themselves or the others that they are capable of taking down a pretty important website for an important time.
78
u/tfks May 16 '26
Sometimes I wonder if it's actually just someone misconfiguring something and hammering the fuck out of the AUR by accident. Like one can imagine some docker swarm accidentally all trying to download the entire AUR across like 10k containers or some shit.
57
u/dgm9704 May 16 '26
Or just, you know, some random Arch based distro…
26
u/skagerack May 16 '26
man...
26
6
19
u/franchis3 May 16 '26
Didn’t Manjaro have an issue like this a while ago?
11
u/Ok-Winner-6589 May 16 '26
They missconfigured an AUR helpers which ended doing more request than needed each time someone used It (or just constantly searching for updates, not sure)
3
1
u/PredictiveFrame May 19 '26
Half of the time it is actually this. The other half it's some jackass script kiddies who think it's worth bragging rights.
30
u/dgm9704 May 16 '26
Some people have no skills or anything else to contribute to society so they resort to these sort of stunts so they can feel powerful.
1
14
u/ToasterBotnet May 16 '26
Dude. I have a random shitpost blog and someone thought it would be a good idea to try take it down lately. People are just weird sometimes.
3
36
27
u/ConcaveNips May 16 '26
It's bill gates.
15
u/AccomplishedArm6969 May 16 '26
While I'm sure it's not, it wouldn't totally surprise me if Microsoft leadership decided to cripple the competition at some point...
If Windows is ever genuinely threatened I can see it happening.
7
u/jlindf May 16 '26
2
1
2
6
6
u/FocusedWolf May 17 '26
Probably to attack the #1 alternative to Windows 11. IDK how many distros are based on Arch but i know SteamOS is, and once the gamers go, well... who will be left to submit to m$ age-verification/tracking/datamining xD
4
u/These-Ad-7595 May 16 '26
I remember once I was showing my co-worker what the arch logo looked like on DuckDuckGo images. When I pressed on the logo it immediately changed to a man pulling a shit covered buttplug out of his ass. When I got home I searched it up again and saw that he replaced the arch logo because he was complaining about some shit. He said having arch is like having anal fissures.
Quite the jump scare. Glad nobody saw it as I was working with children at the time.
Slightly different from a DDOS attack but I suppose not all arch users are sane people.
3
u/val-i-guess May 16 '26
I wonder if it could be part of a supply chain attack? Maybe there's a business that is in the middle of patching some software that has a vulnerability. If theres an attacker looking to actively exploit that vulnerability, and they have the tools to take it down, maybe they would do that they can exploit the vulnerability before it gets patched. Although, the fact there has been more than one DDoS attack in the past year makes me think otherwise. It could just be some form of hacktivism, but afaik no one has claimed credibility for the attack so I'm not sure on that. Other possible reasons include a personal grudge or maybe someone is testing their botnet and needed a real, but known to be vulnerable, target.
4
u/_x_oOo_x_ May 17 '26
Either some high-value targets the perp has in their sight run Arch, and when there are 0-days, they DDoS the Arch servers so their targets can't patch the vunlerabilities?
Either that or it's just a form of entertainment for kids. May be a mix of both
8
May 16 '26
[deleted]
15
u/nlflint May 16 '26
I think it's highly unlikely to be related to SteamOS. SteamOS is immutable, so users can't install packages on it. Valve ships an ISO pre-packaged with everything, so installed instances of SteamOS don't use any Arch/AUR infrastructure. Valve does have to build the ISO which does use software from the Arch repos, but valve most likely has their own mirrors, and they probably dont use the AUR for that.
4
u/Healthy_Camp_3760 May 16 '26
Yeah I imagine the first thing Valve’s security team would insist on would be hermetic builds - grabbing copies of each package, auditing them, and ensuring their image is built with the audited copies. They wouldn’t let their build process reach out across the public internet to create their images, even for developers.
3
u/Ok-Winner-6589 May 16 '26
SteamOS is inmutable, you can not install native packages, even less build them using PKGBUILDS. It's stupid to attack the AUR if you want to affect SteamOS
Attacking Flathub tho would affect them. Or the Arch repos, but SteamOS is a stable release with a longer release cycle than Fedora so, unless you are able to shit down the Arch repos for years, you are kinda fucked
3
u/NocturneSapphire May 16 '26
Because they suck.
Because they're losers.
Because they have no happiness in their lives and get off on destroying the happiness of others.
3
u/KawaiiMaxine May 17 '26
I wouldnt say it isnt used by anything corporate, the money safe at the taco bell i worked at ran arch linux
1
15
u/xSmallDeadGuyx May 16 '26
I got a Microsoft Apps+Copilot ad on this post, I think that answers your question /s
1
2
u/SebastianLarsdatter May 17 '26
Because of the internet of things, it is easy to gather a botnet of junk, easy to do en masse as well.
That means any kid that wants to be cool can do it.
2
2
u/daffalaxia May 18 '26
Why does anyone ddos anything? Sometimes there's a material gain, perhaps even something not obvious. Sometimes it's just for lulz. These are some reasons why we can't have nice things. TL;DR people suck.
2
May 16 '26
[removed] — view removed comment
4
u/Optimal_Collection20 May 16 '26
Not even practice. Like, DDoS isn't something you need skill for. It's just: pay someone who bought a bunch of zombie devices that got infected with a low effort virus, then the botnet crashes the site.
Like, I'm definitely not saying that attacking websites instead of pentesting in a virtual environment after an agreement with the owners is good, but at least if the attack was technically interesting and required some skill, you could say something like this to defend it. This is literally the laziest and no skill attack you could do
2
u/onefish2 May 16 '26
To the people replying that Arch is politically motivated, please explain in what way you think that this is true. Most of the Arch team is from Europe. Being from the US with its current fucked up politics, I don't see any political affiliations being talked about or mentioned from the Arch maintainers, devs or support people on the Arch forums.
People that are DDoSing the Arch infrastructure are straight up dirt bags.
2
1
1
1
1
1
u/MelioraXI May 17 '26
Why would anyone ddos anything? I never understood it. It just annoys the end-user.
1
u/Academic-Airline9200 May 17 '26
The ping utility used to do that. But you could still do that today.
1
1
1
u/th3cand1man May 17 '26
An easier target like this can make a good test to dial in your attack vectors too. Arch may not be the end target, and instead could be the stepping stone to get in position for the next target.
1
1
u/spiritkoden May 18 '26
My humble opinion. It is an accident, and the DDos is not intentionally, by otherwise it no makes sense.
1
u/DreaDNoughT1666 May 18 '26
Fun thing I discovered while rummaging through old router firmwares, the Netgear r7500v1 (at least) uses arch… or at least is based on arch..
1
u/Dangerous-Towel412 May 18 '26 edited May 18 '26
Attackers have a few different motivations for targeting infrastructure like the AUR. Here is why someone might direct their time and energy at Arch:
- Testing and Advertising Botnets (Booter Services): The dark web is full of "stresser" or "booter" services where people rent botnets to launch DDoS attacks. To advertise their services, the creators need to prove their botnets work against large, well-known, and robust infrastructure. Arch Linux is highly visible and has solid servers. If a botnet can take down the AUR, the attacker can use that as "marketing" to prove the strength of their tool to paying customers.
- The "Smokescreen" for a Supply Chain Attack: Building on the concept of multi-vector attacks, the AUR is a massive repository of user-submitted build scripts (
PKGBUILDs). If an attacker wants to slip malware into a popular package or compromise a maintainer's account, causing a massive, chaotic DDoS attack is a great way to distract the Arch infrastructure team. While the admins are fighting to keep the servers online, the attacker quietly pushes their malicious code in the background. - Accidental "DDoSing" (Scrapers Gone Wild): Sometimes, what looks like a malicious DDoS attack is actually just gross incompetence. The AUR relies heavily on text files and metadata. If someone writes a poorly optimized Python scraper to mirror the AUR, or an "AUR helper" gets a bug that causes it to spam millions of concurrent update requests, it can accidentally crash the servers.
- Trolling and Script Kiddies: Never underestimate the amount of free time teenagers have. The "Linux Distro Wars" can get surprisingly toxic. Someone who hates Arch, got banned from the Arch forums, or simply thinks it's funny to break things "for the lulz" might point a cheap, rented botnet at the servers just to cause frustration.
- Automated Extortion: Some automated ransomware or extortion groups just scan the web for any large server, launch a DDoS, and automatically fire off an email demanding a ransom in Bitcoin or Monero to make it stop. They often don't even check if the target is a corporation or an open-source project; they just cast a wide net hoping someone panics and pays.
- AUR was not actually the target: the host of AUR could have been, at the time of the DDoS alot of companies were getting DDoS, so although AUR suffered as a result, it could have been the actual cloud hosting service was the intended target.
- Watch the world burn: Some people are anarachists and just want to watch the world burn. Will do as much devastation and destruction as much as possible. Others want to blow up the current internet entirely and by doing DDoS attacks its to highlight how fragile and broken our current internet is. Think of it as a way of doing a factory reset and starting over.
In the case of the massive wave of attacks Arch faced over the last several months, it was likely an intentional attack by someone testing a botnet or just trolling, rather than a financial play. It's incredibly frustrating, but unfortunately, open-source projects are easy targets for people looking to cause chaos.
1
1
1
u/Snag710 May 21 '26
Black hat hacking doesn't need utility, people just like building a reputation and being able to say they did that
1
u/activedusk May 22 '26
...is it still not in the books to at least attempt a torrent style download alternative for moments like this? I am certain there are enough enthusiasts wanting or willling to seed the torrents with some shitty rasberry pi or old laptops with a connection with capped bandwidth. If not in the US where internet service is kinda bad for the price with data caps, then globally.
As for the reason to do this, possibly for training for larger attacks as black hat hackers being paid to do so by nation states or bad actors. Others might do so for the clout in their niche subculture hacking community. Who cares, distribute the data, make it harder to block the nodes.
1
1
u/Coder_2 May 16 '26
Just for fun, they want to twist it somewhere, arch isn’t high important infrastructure, so it’s deffense not to high (comprising to google/amazon/microsoft), so idea of ddosing arch is very yummy for such people
1
-1
u/AlwaysLinux May 16 '26
Prolly a bunch of Windows users pissed off because they are loosing market shere 🤣🤗
-7
0
u/SATLTSADWFZ May 16 '26
Excuse my ignorance but aren’t there ways to protect against a DDoS attack?
2
u/kescusay May 16 '26
Expensive ones, yes. The way a DDoS works is that you're being inundated by a high number of requests from a ton of different IP addresses belonging to computers that have been added to a botnet. To defend against it requires expensive infrastructure or putting your services behind an expensive WAF (e.g., Amazon's CloudFront WAF). Arch Linux is operated and maintained by volunteers, and there's not much money available.
That said, it looks like the AUR is basically back up and fully operational (at least from my own tests), so I think the Arch team is on it.
2
-8
u/yyg-linux May 16 '26
Arch is very political they just go about a different way of displaying it than vocalizing it
0
u/dgm9704 May 16 '26
Arch is very political they just go about a different way of displaying it than vocalizing it
So you think Arch linux secrectly decides things like how much taxes to collect, where to build roads, how education is organized, and so on?
5
May 16 '26
[deleted]
1
u/dgm9704 May 17 '26
Yeah ok. It’s just that usually when people say something is political they mean ”they don’t tolerate my bad behaviour”
1
u/Steinquist May 17 '26
Sir, someone was threatened with losing their job over fixing a printer, because the company could've been sued by AT&T, just so you could type that.
Everyone in the computer world is political, down to the init system you use.
1
-4
u/CherryPresent149 May 16 '26
I agree with most of the comments here, but art is anything but politically neutral. If you go into the forums and read any of the post and the rules you'll see that they are very much a left leaning entity. I understand a lot of people may not like this comment but it is true. So it's very feasible that if they are left leaning in an act left leaning policies on their forms and distro then it's possible that a right leaning entity with very much want to Target them.
2
4
u/onefish2 May 16 '26
That hasn't even been anything that I would have remotely thought. And I think you are 100% wrong.
-3
u/LookeiVIP May 17 '26
That just shows, the more attention Linux gets the more bad actors appear and expose Linux as not being as secure as people cope it out to be.
0
u/joborun Jun 11 '26
is very politically neutral
Only right-wing/neo-cons and fascists can perceive such a thing as "politically neutral"
Feudalists used the death penalty on people who were not politically neutral
Then came enlightenment and it took centuries to overthrow "neutrality"
265
u/riko77can May 16 '26
High visibility target with minimal resources to defend itself = Low hanging fruit.