Of course the secondary opt-in user repo with unvetted package maintainers is infected with malware, it’d be a miracle if it weren’t! They warn as much in the docs. Use at your own risk, or package and maintain it yourself, because you’re likely not finding it packaged more reliably elsewhere.
And I love Debian, but if you think the Debian repos with 30,000+ packages and 1000+ community maintainers aren’t also infected with malware…
There hasn’t been a single reported incident so far. So, as far as we know… No. They aren’t infected.
And I trust the community of elders that take care of the Debian distro. They have been reliable and solid. They don’t just throw anything at the users on Stable. Even Testing is considered safer than most distributions.
Not even. The PPAs are created and hosted by very specific maintainers with very specific packages. So you have someone to blame and a single software to clean up if things go wrong. And word spreads fast. Yes, there’s a risk, but you can sort of judge how big of a risk it is.
Meanwhile with AUR, it’s just a giant repo in which anybody can just dump whatever. The risks are huge. If I were on Arch, I wouldn’t touch it for anything. I’d rather compile the source code myself for any software I need instead of getting it there.
I’ve been a Linux user for 26 years. I made distros for hardware manufacturers. I know very well the distinctions between the AUR and the regular Arch repos and the parallel with Debian’s.
With Arch, the problem is that the AUR is available in the first place and is very easy to enable. People, especially new users, won’t necessarily understand what they’re getting into when enabling it and getting packages from there. A lot of the advice people get online suggest to get packages from AUR. So Arch users are bound to use it at some point.
And if you add to that the fact that the standard repo has bleeding edge package versions with minimal testing means that vulnerabilities can also get introduced. And it’s happened before. This affected Arch, OpenSUSE Tumbleweed, Fedora, but you know what distribution wasn’t affected? Debian stable and Ubuntu LTS.
And on top of that, I’m not even going to mention how unstable it is and how even just making updates is risky on Arch. You have to be on your toes all the time and you can end up with a broken system at any time. For a main PC operating system, I find that absolutely unacceptable. At least Manjaro tried to improve on this.
Valve switching to Arch makes sense though. They moved to Arch because they wanted the most up to date software and drivers available with a faster release cycle. Then control what versions they push to their devices. They keep a tight control over what gets updated by curating their own repositories. So it’s not purely Arch either. It’s Arch-based. You can expect software to be a little older on Steam OS.
In any case. For me, Debian is the solution. I’m looking for stability and security. It has a huge repo with practically every software under the sun. There’s tons of documentation and support and a huge community. For me the distribution works OOTB without any hitch. I just know that I won’t spend time troubleshooting something on my time off. I already do a lot of this during work.
It’s stable, it has a HUGE software repo (one of the largest ones if I’m not mistaken), third party software and drivers are almost always available as a Debian package, the community behind it is actually serious about making it safe and problem free. So what if some of the software is not bleeding edge? At least I can rest easy when I’m updating my system. I’ll almost never have any bad surprises like you get in Arch.
Arch just takes whatever the latest software is and throws it in the repos for the users to figure out if it breaks. Half the solutions you find in the wiki are half-baked solutions just to make things work, but are often not standard or even secure, leaving your system with security holes.
What makes this a fair argument? Debian not having an AUR analogue? It’s a shit response from someone who couldn’t even be bothered to look up any information on what the AUR is or how it’s supposed to be used. And what exactly is wrong with using debian on a “main pc”? If people want ancient packages with backported security patches they can knock themselves out. It doesn’t fit my requirements, but there’s nothing wrong with it either.
Its rather subjective but it wouldn’t be the first time updating arch has broken my system and its fair that some people don’t want to deal with that and much prefer some more mature.
And i have no qualms with people who do use debian for a main system but i do assume everyone who do are retired folk with a long career in computing behind them and aren’t in the market to change to another.
But that sounds about right. I work in IT and troubleshoot IT problems all day. The last thing I want to do is troubleshoot my PC when I get home. I just want an OS that works. Debian is the best in that regards.
The AUR is not the standard arch package repository and arch as a distro shouldn’t be judged by it’s merits or dangers. Yes, obviously a rolling release distro is not the best fit for most people, but that’s beside the point. Debian is completely fine for people who are looking to replace their windows machine with something stable and don’t need ton of exotic software or especially recent packages.
Who is having breaking update issues anymore in 2026? I’ve been running vanilla Arch for 10 years and the only times that has happened (there have been a handful I guess) the archwiki says “hey there’s a breaking change run these 2 commands” and it’s fixed. As a beginner on Linux I actually switched to Arch because every Ubuntu issue I googled was 6 to 10 lines to fix while arch was 1 to 3 lines. The only problem is that the OS expects that you be able to read, which is sometimes tough.
I can’t imagine being on a system that is multiple major releases behind on basic things like nvim and python. I guess if you’re content not to use anything remotely current it makes sense.
Being behind a few releases isn’t that bad, honestly. At least you’re certain it’s going to be well tested and the majority of problems have been ironed out. And there’ll be documentation already on how to fix things or work around certain missing features if that ever occurs. It’s much less of a hassle.
Why anyone is using Arch at this point is beyond me.
Every update is a potential failure waiting to happen. And on top of that, their user repos are infected with malware.
Yeah, I’m going to stick with Debian.
Of course the secondary opt-in user repo with unvetted package maintainers is infected with malware, it’d be a miracle if it weren’t! They warn as much in the docs. Use at your own risk, or package and maintain it yourself, because you’re likely not finding it packaged more reliably elsewhere.
And I love Debian, but if you think the Debian repos with 30,000+ packages and 1000+ community maintainers aren’t also infected with malware…
There hasn’t been a single reported incident so far. So, as far as we know… No. They aren’t infected.
And I trust the community of elders that take care of the Debian distro. They have been reliable and solid. They don’t just throw anything at the users on Stable. Even Testing is considered safer than most distributions.
deleted by creator
Not even. The PPAs are created and hosted by very specific maintainers with very specific packages. So you have someone to blame and a single software to clean up if things go wrong. And word spreads fast. Yes, there’s a risk, but you can sort of judge how big of a risk it is.
Meanwhile with AUR, it’s just a giant repo in which anybody can just dump whatever. The risks are huge. If I were on Arch, I wouldn’t touch it for anything. I’d rather compile the source code myself for any software I need instead of getting it there.
deleted by creator
deleted by creator
deleted by creator
I’ve been a Linux user for 26 years. I made distros for hardware manufacturers. I know very well the distinctions between the AUR and the regular Arch repos and the parallel with Debian’s.
With Arch, the problem is that the AUR is available in the first place and is very easy to enable. People, especially new users, won’t necessarily understand what they’re getting into when enabling it and getting packages from there. A lot of the advice people get online suggest to get packages from AUR. So Arch users are bound to use it at some point.
And if you add to that the fact that the standard repo has bleeding edge package versions with minimal testing means that vulnerabilities can also get introduced. And it’s happened before. This affected Arch, OpenSUSE Tumbleweed, Fedora, but you know what distribution wasn’t affected? Debian stable and Ubuntu LTS.
And on top of that, I’m not even going to mention how unstable it is and how even just making updates is risky on Arch. You have to be on your toes all the time and you can end up with a broken system at any time. For a main PC operating system, I find that absolutely unacceptable. At least Manjaro tried to improve on this.
Valve switching to Arch makes sense though. They moved to Arch because they wanted the most up to date software and drivers available with a faster release cycle. Then control what versions they push to their devices. They keep a tight control over what gets updated by curating their own repositories. So it’s not purely Arch either. It’s Arch-based. You can expect software to be a little older on Steam OS.
In any case. For me, Debian is the solution. I’m looking for stability and security. It has a huge repo with practically every software under the sun. There’s tons of documentation and support and a huge community. For me the distribution works OOTB without any hitch. I just know that I won’t spend time troubleshooting something on my time off. I already do a lot of this during work.
deleted by creator
deleted by creator
Being critical towards operating system: Great
Actual argument: fair
Solution: oof
Debian is by all means great, for many things, but for a main pc? Shivers
Why shivers ?
It’s stable, it has a HUGE software repo (one of the largest ones if I’m not mistaken), third party software and drivers are almost always available as a Debian package, the community behind it is actually serious about making it safe and problem free. So what if some of the software is not bleeding edge? At least I can rest easy when I’m updating my system. I’ll almost never have any bad surprises like you get in Arch.
Arch just takes whatever the latest software is and throws it in the repos for the users to figure out if it breaks. Half the solutions you find in the wiki are half-baked solutions just to make things work, but are often not standard or even secure, leaving your system with security holes.
What makes this a fair argument? Debian not having an AUR analogue? It’s a shit response from someone who couldn’t even be bothered to look up any information on what the AUR is or how it’s supposed to be used. And what exactly is wrong with using debian on a “main pc”? If people want ancient packages with backported security patches they can knock themselves out. It doesn’t fit my requirements, but there’s nothing wrong with it either.
Its rather subjective but it wouldn’t be the first time updating arch has broken my system and its fair that some people don’t want to deal with that and much prefer some more mature.
And i have no qualms with people who do use debian for a main system but i do assume everyone who do are retired folk with a long career in computing behind them and aren’t in the market to change to another.
LOL! I’m not THAT old hahahahaha!
But that sounds about right. I work in IT and troubleshoot IT problems all day. The last thing I want to do is troubleshoot my PC when I get home. I just want an OS that works. Debian is the best in that regards.
The AUR is not the standard arch package repository and arch as a distro shouldn’t be judged by it’s merits or dangers. Yes, obviously a rolling release distro is not the best fit for most people, but that’s beside the point. Debian is completely fine for people who are looking to replace their windows machine with something stable and don’t need ton of exotic software or especially recent packages.
deleted by creator
Who is having breaking update issues anymore in 2026? I’ve been running vanilla Arch for 10 years and the only times that has happened (there have been a handful I guess) the archwiki says “hey there’s a breaking change run these 2 commands” and it’s fixed. As a beginner on Linux I actually switched to Arch because every Ubuntu issue I googled was 6 to 10 lines to fix while arch was 1 to 3 lines. The only problem is that the OS expects that you be able to read, which is sometimes tough.
I can’t imagine being on a system that is multiple major releases behind on basic things like nvim and python. I guess if you’re content not to use anything remotely current it makes sense.
Being behind a few releases isn’t that bad, honestly. At least you’re certain it’s going to be well tested and the majority of problems have been ironed out. And there’ll be documentation already on how to fix things or work around certain missing features if that ever occurs. It’s much less of a hassle.
@webghost0101 @ZombieCyborgFromOuterSpace You are weird.
I wouldn’t want to be perceived in any other way.