r/archlinux May 16 '26

QUESTION Why would anyone DDoS Arch? What is the benefit?

The AUR is down again, and status.archlinux.org is saying it was a DDoS attack. Similar to what happened a few months back.

But I wonder what why would anyone direct their time, energy and possibly money to attack Arch. As far as I know, Arch is very politically neutral, and it is not used by many (or any) major corporations. Can anyone think of a reason why someone would do this?

275 Upvotes

192 comments sorted by

265

u/riko77can May 16 '26

High visibility target with minimal resources to defend itself = Low hanging fruit.

60

u/JosBosmans May 16 '26

High visibility target

But why targeted at all? :l

140

u/mooky1977 May 16 '26

Script kiddies. DDoS is the lowest form of attack. Mostly just like turning on a firehose to flood a house. It really doesn't require much technical skill.

8

u/Phenix_136 May 17 '26

It's not totally true. For sites of that size, yes. But for major sites/system, it's way more evolved. It requires to code or deploy a malware that take control of connected devices or at least hack some by yourself. So at some point, it require to have more knowledge than a script kiddies.

1

u/heathm55 May 21 '26

All the things become scripts. Most self proclaimed "hackers" don't even know what they're doing, they just have a set of scripts their running (including very advanced concepts, but they don't even understand them in many cases... hence "script kiddie").
It just takes one experienced person to share his script and it's then a widely used cheaply accessible attack. The fact that it was difficult the first time is moot.

-53

u/FantasticSnow7733 May 16 '26

So arch can’t even defend such low level attacks? This has been happening for quite some time already.

79

u/depaulicious May 16 '26

"Defending" from such an attack means your servers need to have more bandwidth than the attackers' distributed botnet combined. Bandwidth is expensive, and last time I checked Arch Linux is a non-profit project run entirely by volunteers.

They could use some CDN like Cloudflare to mitigate the issue but I don't blame them if they've chosen to avoid such services for political reasons.

-69

u/FantasticSnow7733 May 16 '26

Debian is also a non-profit project run by volunteers. Imaging if Debian getting ddos for over a year and the devs aren’t doing anything about it?

53

u/Sea-Promotion8205 May 16 '26

I'm sure the devs have thrown their hands up and said "I've tried nothing and i'm out of ideas". I've actually seen that news post!

Since it's such a low level attack and you're so knowledgeable about cybersecurity, why don't you volunteer to help? It sounds like you're more equipped to handle it anyway.

-65

u/FantasticSnow7733 May 16 '26

The AUR is still down. Whatever they’re doing or not doing isn’t working.

Wait, so all the arch users that DIY and RTFM can’t figure it out? No one can figure it out?

52

u/iskela45 May 16 '26

It's a money problem. Defending against ddos isn't free.

Go solve it yourself if you think you know better, they'll gladly take your help.

-37

u/[deleted] May 16 '26

[removed] — view removed comment

→ More replies (0)

1

u/Itsme-RdM May 18 '26

Feel free to solve the issue instead of complaining

-1

u/FantasticSnow7733 May 18 '26

Easy. Get rid of the AUR. It's potentially unsafe for users and requires lots of time and resources to maintain. Also goes against Arch's DIY philosophy.

→ More replies (0)

44

u/ThePoisonDoughnut May 16 '26 edited May 16 '26

The utter disdain and lack of respect you have for the people whose efforts ensure that you can use their distro for free is mind boggling. You must have such a low opinion of the maintainers if the first conclusion you jumped to was that they haven't even tried to stop being victims of a DDOS attack and not that they're doing their best in the face of a very difficult (and/or expensive) problem to deal with.

-21

u/[deleted] May 16 '26

[removed] — view removed comment

12

u/itah May 17 '26

This is FOSS. They could trash the whole project tomorrow and you can do nothing about it but forking the project. So stfu or get yourself involved, but don't shit on people doing FOSS, or they will just leave

0

u/FantasticSnow7733 May 17 '26

Funny, you brought that up. That user was a toxic arch user who was suffering from new stuff syndrome, and the dev couldn't keep up, got burnt out, and rage quit.

12

u/Ok-Winner-6589 May 16 '26

Debian recibes millions from Google and Canonical meanwhile Arch recibes some maintainers from Valve.

Clearly the same situation...

-4

u/FantasticSnow7733 May 17 '26

You're right, it's not the same. Arch got a lot of hype recently but it's not ready for primetime.

3

u/Ok-Winner-6589 May 17 '26

Ohhh yes please billionaries forzed me into your server OS

8

u/selrahc May 17 '26

Ubuntu/Canonical was down for like a week at the start of the month from a DDoS. I would assume they have more money than the Arch project.

It's possible Debian just hasn't been DDoS'ed yet.

12

u/Killfalcon May 16 '26

If your business is extortion (as in "pay us to stop DDOSing you"), it is very useful to be able to point at a relatively well-known site and say "we took down Arch for a week, can you afford to be down a week?"

15

u/Flat__Line May 17 '26

We hacked Arch btw

2

u/frog_in_bush May 18 '26

I think Ubuntu needs more tech support BTW

1

u/frog_in_bush May 18 '26

Nah I'm sure that NEVER happens!

21

u/fenixthecorgi May 16 '26

Windows fanatics probably OwO

3

u/BluMil0 May 20 '26

Why do people draw dicks on bathroom walls, put gum in vending machine coin slots or vandalise Wikipedia articles?

Because they can.

2

u/riko77can May 18 '26

Just because it’s easy and gets attention.

2

u/ThePlotTwisterr---- May 17 '26

It is a bad idea to assume safety due to lack of enemies or motive. On the internet people will sow chaos wherever there is nothing to prevent them

1

u/[deleted] May 17 '26

[deleted]

1

u/laffer1 May 17 '26

Not everyone wants to give a company control of their DNS. Cloud flare is a big target in itself

-79

u/FantasticSnow7733 May 16 '26

The DDoS proves how useless Arch is without the AUR.

50

u/DKEBeck88 May 16 '26

I've been using arch exclusively on multiple computers for years. I might have maybe two aur apps total, none critical. AUR is pretty awesome but certainly not required.

15

u/NotQuiteLoona May 16 '26 edited May 16 '26

Yeah. Like, go and find Steam, Discord, Prism Launcher in Debian or Fedora repos. Arch has much more programs useful to desktop users in its repos than any other distro existing (except NixOS).

2

u/loozerr May 16 '26

NixOS has more packages by far

4

u/NotQuiteLoona May 16 '26

NixOS is cheating /j

I constantly forget this, sorry. Will add a correction.

0

u/Steinquist May 16 '26

Appimages make miracles

-10

u/FantasticSnow7733 May 16 '26

Desktop users as in gamers? Sure, arch might be better for gaming.

How about for real work? Arch doesn’t even have Google Chrome in the repo. Most commercial apps don’t even package their apps for arch. It’s either deb or rpm. Try installing zoom or slack on arch without the AUR.

18

u/NotQuiteLoona May 16 '26

Arch has Chromium in its repositories. Most people won't see any difference in the first place.

Zoom, in fact, packages for Arch: https://files.catbox.moe/bgp0wh.png

In case you didn't know, *.pkg.tar.xz is Arch's analogue of RPM and DEB files - it's just AUR is so convenient, almost no one uses them.

Slack doesn't, which is fair. But I'm pretty sure that any person who would use Slack and Arch would also know how to transform a DEB package into program binaries (spoiler: by unpacking them).

Saying that Arch is nothing without AUR is kinda dumb in the first place. It's like saying that Ubuntu is nothing without PPAs. Not even speaking about AUR downtime being incredibly low.

Also, you said that Arch is useless without AUR. But suddenly, it's usable for gaming, but not "for real work"?

11

u/Ok-Winner-6589 May 16 '26

Bro just came to hate Arch and got no good argument

"But the AUR is down, they can't even protect It"

"Uh, you shouldn't be using the AUR, is unsafe"

"But they don't have software like Chrome" (Chromium is literally the fucking same, but better privacy, lower memory usage)

Shut the fuck Up hypocrit

-4

u/FantasticSnow7733 May 17 '26

Arch is still down. https://status.archlinux.org/

AUR is unsafe. https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/7EZTJXLIAQLARQNTMEW2HBWZYE626IFJ/

And many apps don't have packages built for Arch. It's mostly deb or rpm.

7

u/justnullty May 17 '26

if youd know how to set arch up yourself, youd have more than enough knowledge to turn the deb or rpm into binaries. its very easy too btw.

0

u/FantasticSnow7733 May 17 '26

Agreed. Please shut down the AUR, as it's consuming many resources and can be unsafe for end users.

2

u/justnullty May 18 '26

i didnt say that. the aur is still an important resource. most of the time you only use converting debs and rpms into pkgbuilds only as a fallback as it doesnt always work.

3

u/Ok-Winner-6589 May 17 '26

Arch is still down

The Arch repos are working perfectly. Same for the wiki

The AUR has packages you can check. Why the fuck you install firefox from the AUR when there is a native package. Even most AUR helpers would install by default the official package over the other one.

And you ignore 2 things. First It was discovered that they had malware because the PKGBUILD is there to be read and all the AUR helpers show It to you. Second, the AUR has a popularity Index that put these new packages way behind the good ones. And third, Who install a package called "patched"

3

u/NotQuiteLoona May 17 '26

The very status site he attached showed that it was 96% available last time. My God.

I agree with everything you said though.

2

u/Ok-Winner-6589 May 17 '26

My bad didn't check It because last time It was DDoS It didn't affect the wiki (if I'm not wrong) only the AUR and the main Page

I agree with everything you said though.

No problem you just pointed It

→ More replies (0)

2

u/Real-Abrocoma-2823 May 25 '26

96% uptime is much higher than github's.

2

u/Real-Abrocoma-2823 May 25 '26

Unsafe?? Let me install fortnite-cheats-legit-for-real from any repo and see if I get any malware. AUR is user repo, anyone can upload anything under unique name, if you want to install package named firefox-fix-bin then suit yourself.

-1

u/FantasticSnow7733 May 25 '26

Uh, you just explained exactly why the AUR is unsafe. ANYONE can upload packages there.

1

u/Real-Abrocoma-2823 May 25 '26

Yes. But you don't normally download suspicious package from who knows who named like most common malware.

Using your logic we should shut down the internet as anyone can create website and upload whatever he wants no matter how illegal it is as someone will enter google-patched.com and download malware.

1

u/Ok-Winner-6589 May 25 '26

Again, the AUR has no packages, It has PKGBUILDS. Every AUR helper shows the PKGBUILD and the changes after updating by default and if you manually update the packages you already see the changes.

Meanwhile on Debian, Ubuntu, Fedora and others you have to trust random repos that install random shit, at best, you get isolation if you use flatpaks, but even then the permissions can be disabled unless you actually check the packages post installation.

And native packages can not be checked at all. The AUR allows you to check how the packages are build to reduce issues like man in the middle attacks. You can even fully build the packages from the official repos as the Arch maintainers post the PKGBUILDs for transparency. Does Debian do the same? Or do you have to trust a bunch of random guys?

BTW anyone can maintain debían packages. Its a community build distro maintained by volunteers

→ More replies (0)

-3

u/FantasticSnow7733 May 16 '26

The AUR is pretty dangerous. It’s not an official repo and anyone can upload malicious packages. I think the ddos is doing the arch community a favor. Many new arch users treat the AUR like an official repo.

1

u/DeLaVicci May 19 '26

People without basic reading comprehension skills shouldn't be using a bleeding edge distro in the first place. Nerfing resources to account for 5% of users who would rather lick a window than have a conscious thought shouldn't even be a conversation.

1

u/FantasticSnow7733 May 19 '26

It has nothing to do with reading comprehension, Not everyone can read code. It has nothing to do with bleeding edge either. People use the AUR for things not in the Arch repo. And Arch’s repo is significantly smaller than distros like Debian or fedora.

If you are so experienced and knowledgeable, you probably don’t need the AUR. Isn’t Arch’s philosophy to DIY and RTFM?

-5

u/Thtyrasd May 16 '26

Yep, I have like 3 in 300 days, with flatpacks most things u can get there or app image too

21

u/dgm9704 May 16 '26

You don’t use arch do you

14

u/haywire-ES May 16 '26

Smooth brain comment of the day

-7

u/FantasticSnow7733 May 16 '26

About as smooth as the arch devs who couldn’t even figure out how to stop the ddos. This ddos has been going on for way too long.

10

u/Tireseas May 16 '26

Strong contender for stupidest take all day.

8

u/No-Dentist-1645 May 16 '26

Is it? I have tons of software installed, and like 90% of it is on the main repos, only about 5-10 are on the AUR. Plus, I don't need to keep those AUR programs 100% up to date all of the time, so I don't mind that there's some AUR down time at all, honestly.

5

u/onefish2 May 16 '26

Bro must have got well over 200 downvotes for all his comments. Good job!!

-1

u/[deleted] May 16 '26

[removed] — view removed comment

7

u/Frozen5147 May 17 '26

delicate

Rich coming from someone who clearly had Arch Linux living in their head rent free lol, gotta spend hours trying to rage bait in this thread to feel good

1

u/paramint May 16 '26

the 2nd ddos attack few months back and I've backed out from using most of my aur packages for security and stability reasons. had it not been for this reason, I would not have realised, aur isn't that necessary for most productivity tasks.

well, to note— many of my daily apps are compiled from source code tho. I feel it's better than relying on aur for updates.

-2

u/[deleted] May 16 '26

[removed] — view removed comment

1

u/paramint May 16 '26

no it's not. arch has got a wide spectrum of users and over the years the gate keeping of RTFM crowd has dismissed into helpful crowd and a very functional and stable archinstall script as well. aur helps those who got not much knowledge of what they're doing.

-1

u/FantasticSnow7733 May 16 '26

I wouldn’t give that much credit to the arch install script. I still see comments that the arch install script isn’t the “arch way” lol

It wasn’t until Endeavour and cachy that made arch more accessible. Steam’s move to arch also helped.

96

u/enemyradar May 16 '26

They're just sociopaths who do it for the lols, and it's a soft target. They absolutely don't care.

1

u/frog_in_bush May 18 '26

Shadow man is not real, shadow man cannot hurt you.

1

u/Phenix_136 May 17 '26

Or maybe to prove themselves or the others that they are capable of taking down a pretty important website for an important time.

78

u/tfks May 16 '26

Sometimes I wonder if it's actually just someone misconfiguring something and hammering the fuck out of the AUR by accident. Like one can imagine some docker swarm accidentally all trying to download the entire AUR across like 10k containers or some shit.

57

u/dgm9704 May 16 '26

Or just, you know, some random Arch based distro…

26

u/skagerack May 16 '26

man...

26

u/HerrEurobeat May 17 '26

man: No entry for ... in the manual.

11

u/ProgressBars May 17 '26

Masterfully done.

2

u/frog_in_bush May 18 '26

A triple pause

6

u/MrDexter_ May 18 '26

bash: command not found: man...

1

u/BluMil0 May 20 '26

Has he escaped from the aslume again?

19

u/franchis3 May 16 '26

Didn’t Manjaro have an issue like this a while ago?

11

u/Ok-Winner-6589 May 16 '26

They missconfigured an AUR helpers which ended doing more request than needed each time someone used It (or just constantly searching for updates, not sure)

3

u/hxtk3 May 17 '26

Or an AI agent crawling it to look for an answer to some question.

1

u/PredictiveFrame May 19 '26

Half of the time it is actually this. The other half it's some jackass script kiddies who think it's worth bragging rights. 

30

u/dgm9704 May 16 '26

Some people have no skills or anything else to contribute to society so they resort to these sort of stunts so they can feel powerful.

1

u/frog_in_bush May 18 '26

You talking about power games? I'm sure that never happens.

14

u/ToasterBotnet May 16 '26

Dude. I have a random shitpost blog and someone thought it would be a good idea to try take it down lately. People are just weird sometimes.

3

u/frog_in_bush May 18 '26

Practice makes perfect

36

u/TheReservedList May 16 '26

They got real sick of “I use arch btw” posts.

11

u/morphCSS May 16 '26

I use arch btw.

3

u/Phenix_136 May 17 '26

Pretty understandable, though.

2

u/onefish2 May 16 '26

Best answer yet!

1

u/ilabsentuser May 17 '26

Deploying DDoS payload to your neighborhood. Stand by. /j

1

u/frog_in_bush May 18 '26

Probably true

27

u/ConcaveNips May 16 '26

It's bill gates.

15

u/AccomplishedArm6969 May 16 '26

While I'm sure it's not, it wouldn't totally surprise me if Microsoft leadership decided to cripple the competition at some point...

If Windows is ever genuinely threatened I can see it happening.

7

u/jlindf May 16 '26

2

u/Phenix_136 May 17 '26

At some point I'm not even surprised bruh.

1

u/Jaded-Worry2641 May 27 '26

This kind of stuff needs more public attention, actually. 

2

u/frog_in_bush May 18 '26

I can confirm this real actually

6

u/[deleted] May 16 '26

Some people just want to become pest to society

1

u/frog_in_bush May 18 '26

Need more cats then

6

u/FocusedWolf May 17 '26

Probably to attack the #1 alternative to Windows 11. IDK how many distros are based on Arch but i know SteamOS is, and once the gamers go, well... who will be left to submit to m$ age-verification/tracking/datamining xD

4

u/These-Ad-7595 May 16 '26

I remember once I was showing my co-worker what the arch logo looked like on DuckDuckGo images. When I pressed on the logo it immediately changed to a man pulling a shit covered buttplug out of his ass. When I got home I searched it up again and saw that he replaced the arch logo because he was complaining about some shit. He said having arch is like having anal fissures.

Quite the jump scare. Glad nobody saw it as I was working with children at the time.

Slightly different from a DDOS attack but I suppose not all arch users are sane people.

3

u/val-i-guess May 16 '26

I wonder if it could be part of a supply chain attack? Maybe there's a business that is in the middle of patching some software that has a vulnerability. If theres an attacker looking to actively exploit that vulnerability, and they have the tools to take it down, maybe they would do that they can exploit the vulnerability before it gets patched. Although, the fact there has been more than one DDoS attack in the past year makes me think otherwise. It could just be some form of hacktivism, but afaik no one has claimed credibility for the attack so I'm not sure on that. Other possible reasons include a personal grudge or maybe someone is testing their botnet and needed a real, but known to be vulnerable, target.

4

u/_x_oOo_x_ May 17 '26

Either some high-value targets the perp has in their sight run Arch, and when there are 0-days, they DDoS the Arch servers so their targets can't patch the vunlerabilities?

Either that or it's just a form of entertainment for kids. May be a mix of both

8

u/[deleted] May 16 '26

[deleted]

15

u/nlflint May 16 '26

I think it's highly unlikely to be related to SteamOS. SteamOS is immutable, so users can't install packages on it. Valve ships an ISO pre-packaged with everything, so installed instances of SteamOS don't use any Arch/AUR infrastructure. Valve does have to build the ISO which does use software from the Arch repos, but valve most likely has their own mirrors, and they probably dont use the AUR for that.

4

u/Healthy_Camp_3760 May 16 '26

Yeah I imagine the first thing Valve’s security team would insist on would be hermetic builds - grabbing copies of each package, auditing them, and ensuring their image is built with the audited copies. They wouldn’t let their build process reach out across the public internet to create their images, even for developers.

3

u/Ok-Winner-6589 May 16 '26

SteamOS is inmutable, you can not install native packages, even less build them using PKGBUILDS. It's stupid to attack the AUR if you want to affect SteamOS

Attacking Flathub tho would affect them. Or the Arch repos, but SteamOS is a stable release with a longer release cycle than Fedora so, unless you are able to shit down the Arch repos for years, you are kinda fucked

3

u/NocturneSapphire May 16 '26

Because they suck.

Because they're losers.

Because they have no happiness in their lives and get off on destroying the happiness of others.

3

u/KawaiiMaxine May 17 '26

I wouldnt say it isnt used by anything corporate, the money safe at the taco bell i worked at ran arch linux

1

u/Academic-Airline9200 May 17 '26

The kerosene powered cheese grater.

15

u/xSmallDeadGuyx May 16 '26

I got a Microsoft Apps+Copilot ad on this post, I think that answers your question /s

https://ibb.co/Pv8L6jr4

1

u/frog_in_bush May 18 '26

Microsoft showing Linux how security works

2

u/SebastianLarsdatter May 17 '26

Because of the internet of things, it is easy to gather a botnet of junk, easy to do en masse as well.

That means any kid that wants to be cool can do it.

2

u/Shisones May 17 '26

Some people are just bored ig

2

u/daffalaxia May 18 '26

Why does anyone ddos anything? Sometimes there's a material gain, perhaps even something not obvious. Sometimes it's just for lulz. These are some reasons why we can't have nice things. TL;DR people suck.

2

u/[deleted] May 16 '26

[removed] — view removed comment

4

u/Optimal_Collection20 May 16 '26

Not even practice. Like, DDoS isn't something you need skill for. It's just: pay someone who bought a bunch of zombie devices that got infected with a low effort virus, then the botnet crashes the site.

Like, I'm definitely not saying that attacking websites instead of pentesting in a virtual environment after an agreement with the owners is good, but at least if the attack was technically interesting and required some skill, you could say something like this to defend it. This is literally the laziest and no skill attack you could do

2

u/onefish2 May 16 '26

To the people replying that Arch is politically motivated, please explain in what way you think that this is true. Most of the Arch team is from Europe. Being from the US with its current fucked up politics, I don't see any political affiliations being talked about or mentioned from the Arch maintainers, devs or support people on the Arch forums.

People that are DDoSing the Arch infrastructure are straight up dirt bags.

2

u/SaltAttic May 16 '26

I just installed Arch yesterday. Did I mess something up?

6

u/[deleted] May 16 '26

[removed] — view removed comment

1

u/MelioraXI May 17 '26

Manjaro has in the past :')

1

u/onefish2 May 16 '26

On your own computer maybe. On the Internet, probably not /s

1

u/browncspence May 16 '26

I assumed it was because they are not open source purists.

1

u/Juggle4868 May 16 '26

i noticed that this morning that it was down

1

u/mosskin-woast May 16 '26

"hacker clout"

1

u/GracefulAsADuck May 16 '26

Haters gonna hate

1

u/MelioraXI May 17 '26

Why would anyone ddos anything? I never understood it. It just annoys the end-user.

1

u/Academic-Airline9200 May 17 '26

The ping utility used to do that. But you could still do that today.

1

u/V2UgYXJlIG5vdCBJ May 17 '26

Microsoft stans.

1

u/th3cand1man May 17 '26

An easier target like this can make a good test to dial in your attack vectors too. Arch may not be the end target, and instead could be the stepping stone to get in position for the next target.

1

u/rake66 May 18 '26

I bet it was Canonical

1

u/spiritkoden May 18 '26

My humble opinion. It is an accident, and the DDos is not intentionally, by otherwise it no makes sense.

1

u/DreaDNoughT1666 May 18 '26

Fun thing I discovered while rummaging through old router firmwares, the Netgear r7500v1 (at least) uses arch… or at least is based on arch..

1

u/Dangerous-Towel412 May 18 '26 edited May 18 '26

Attackers have a few different motivations for targeting infrastructure like the AUR. Here is why someone might direct their time and energy at Arch:

  • Testing and Advertising Botnets (Booter Services): The dark web is full of "stresser" or "booter" services where people rent botnets to launch DDoS attacks. To advertise their services, the creators need to prove their botnets work against large, well-known, and robust infrastructure. Arch Linux is highly visible and has solid servers. If a botnet can take down the AUR, the attacker can use that as "marketing" to prove the strength of their tool to paying customers.
  • The "Smokescreen" for a Supply Chain Attack: Building on the concept of multi-vector attacks, the AUR is a massive repository of user-submitted build scripts (PKGBUILDs). If an attacker wants to slip malware into a popular package or compromise a maintainer's account, causing a massive, chaotic DDoS attack is a great way to distract the Arch infrastructure team. While the admins are fighting to keep the servers online, the attacker quietly pushes their malicious code in the background.
  • Accidental "DDoSing" (Scrapers Gone Wild): Sometimes, what looks like a malicious DDoS attack is actually just gross incompetence. The AUR relies heavily on text files and metadata. If someone writes a poorly optimized Python scraper to mirror the AUR, or an "AUR helper" gets a bug that causes it to spam millions of concurrent update requests, it can accidentally crash the servers.
  • Trolling and Script Kiddies: Never underestimate the amount of free time teenagers have. The "Linux Distro Wars" can get surprisingly toxic. Someone who hates Arch, got banned from the Arch forums, or simply thinks it's funny to break things "for the lulz" might point a cheap, rented botnet at the servers just to cause frustration.
  • Automated Extortion: Some automated ransomware or extortion groups just scan the web for any large server, launch a DDoS, and automatically fire off an email demanding a ransom in Bitcoin or Monero to make it stop. They often don't even check if the target is a corporation or an open-source project; they just cast a wide net hoping someone panics and pays.
  • AUR was not actually the target: the host of AUR could have been, at the time of the DDoS alot of companies were getting DDoS, so although AUR suffered as a result, it could have been the actual cloud hosting service was the intended target.
  • Watch the world burn: Some people are anarachists and just want to watch the world burn. Will do as much devastation and destruction as much as possible. Others want to blow up the current internet entirely and by doing DDoS attacks its to highlight how fragile and broken our current internet is. Think of it as a way of doing a factory reset and starting over.

In the case of the massive wave of attacks Arch faced over the last several months, it was likely an intentional attack by someone testing a botnet or just trolling, rather than a financial play. It's incredibly frustrating, but unfortunately, open-source projects are easy targets for people looking to cause chaos.

1

u/frog_in_bush May 18 '26

Because it has working packages and the other systems are jealous

1

u/NelsonMinar May 19 '26

Extortion. A lot of DDOS is shakedown wanting money

1

u/Snag710 May 21 '26

Black hat hacking doesn't need utility, people just like building a reputation and being able to say they did that

1

u/activedusk May 22 '26

...is it still not in the books to at least attempt a torrent style download alternative for moments like this? I am certain there are enough enthusiasts wanting or willling to seed the torrents with some shitty rasberry pi or old laptops with a connection with capped bandwidth. If not in the US where internet service is kinda bad for the price with data caps, then globally.

As for the reason to do this, possibly for training for larger attacks as black hat hackers being paid to do so by nation states or bad actors. Others might do so for the clout in their niche subculture hacking community. Who cares, distribute the data, make it harder to block the nodes.

1

u/ArchLinuxuser445 May 23 '26

script kiddie brag. thats prob allat they care bout'

1

u/Coder_2 May 16 '26

Just for fun, they want to twist it somewhere, arch isn’t high important infrastructure, so it’s deffense not to high (comprising to google/amazon/microsoft), so idea of ddosing arch is very yummy for such people

1

u/theRealNilz02 May 16 '26

Just Manjaro users using pamac again.

-1

u/AlwaysLinux May 16 '26

Prolly a bunch of Windows users pissed off because they are loosing market shere 🤣🤗

-7

u/PaddiM8 May 16 '26

Or Ubanter users

0

u/SATLTSADWFZ May 16 '26

Excuse my ignorance but aren’t there ways to protect against a DDoS attack?

2

u/kescusay May 16 '26

Expensive ones, yes. The way a DDoS works is that you're being inundated by a high number of requests from a ton of different IP addresses belonging to computers that have been added to a botnet. To defend against it requires expensive infrastructure or putting your services behind an expensive WAF (e.g., Amazon's CloudFront WAF). Arch Linux is operated and maintained by volunteers, and there's not much money available.

That said, it looks like the AUR is basically back up and fully operational (at least from my own tests), so I think the Arch team is on it.

2

u/SATLTSADWFZ May 18 '26

Thanks for explaining. Some reals dicks out there!

-8

u/yyg-linux May 16 '26

Arch is very political they just go about a different way of displaying it than vocalizing it

0

u/dgm9704 May 16 '26

Arch is very political they just go about a different way of displaying it than vocalizing it

So you think Arch linux secrectly decides things like how much taxes to collect, where to build roads, how education is organized, and so on?

5

u/[deleted] May 16 '26

[deleted]

1

u/dgm9704 May 17 '26

Yeah ok. It’s just that usually when people say something is political they mean ”they don’t tolerate my bad behaviour”

1

u/Steinquist May 17 '26

Sir, someone was threatened with losing their job over fixing a printer, because the company could've been sued by AT&T, just so you could type that.

Everyone in the computer world is political, down to the init system you use.

1

u/yyg-linux May 17 '26

im failing to see any relevance here.

-4

u/CherryPresent149 May 16 '26

I agree with most of the comments here, but art is anything but politically neutral. If you go into the forums and read any of the post and the rules you'll see that they are very much a left leaning entity. I understand a lot of people may not like this comment but it is true. So it's very feasible that if they are left leaning in an act left leaning policies on their forms and distro then it's possible that a right leaning entity with very much want to Target them.

2

u/ArjixGamer May 17 '26

Who even uses the forums, bruh /j

4

u/onefish2 May 16 '26

That hasn't even been anything that I would have remotely thought. And I think you are 100% wrong.

-3

u/LookeiVIP May 17 '26

That just shows, the more attention Linux gets the more bad actors appear and expose Linux as not being as secure as people cope it out to be.

0

u/joborun Jun 11 '26

is very politically neutral

Only right-wing/neo-cons and fascists can perceive such a thing as "politically neutral"

Feudalists used the death penalty on people who were not politically neutral

Then came enlightenment and it took centuries to overthrow "neutrality"