3 ms·
The problem is that there's a lot of software out there that expects you to install it this way - particularly by piping into sh or bash or the like. See also h
by Albright 11y ago
The problem is that there's a lot of software out there that expects you to install it this way - particularly by piping into sh or bash or the like. See also http://www.seancassidy.me/dont-pipe-to-your-shell.html http://www.seancassidy.me/dont-pipe-to-your-shell.html and http://output.chrissnell.com/post/69023793377/stop-piping-curl1-to-sh1 http://output.chrissnell.com/post/69023793377/stop-piping-cu... and https://www.chef.io/blog/2015/07/16/5-ways-to-deal-with-the-install-sh-curl-pipe-bash-problem/ https://www.chef.io/blog/2015/07/16/5-ways-to-deal-with-the-... . There was also a blog out there collecting instances of this, but I couldn't find it again after a couple searches.
I had to hold my nose and paste some commands like this in order to reinstall Composer [1] and Drupal Console [2] earlier this week. Ugh, it feels so dirty, but it's often the first and/or the easiest, if not the only, way that software like this documents how it's to be installed.
1. https://getcomposer.org/doc/00-intro.md#globally https://getcomposer.org/doc/00-intro.md#globally
2. http://drupalconsole.com http://drupalconsole.com
- dublinben 11y agoNone of those commands are so long that you shouldn't just be retyping them by hand. It's obviously not an ideal way to install anything, but it's much safer than copy and pasting.
- cortesoft 11y agoor copy them to a text editor first?
- jeffdavis 11y agoIs that safe? (Legitimate question)
- keithgabryelski 11y agoone can target specific editors... for instance, if I know you are using VI I can create a series of characters that will escape out of insert mode and run a shell command (note: ^[ is ESC (ascii 27)) git status ^[ :!echo foo
- robotkilla 11y agoI ran into this for the first time just recently when installing ruby and was very surprised and hesitant to follow the instructions ( see here https://www.digitalocean.com/community/tutorials/how-to-install-ruby-on-rails-on-ubuntu-14-04-using-rvm https://www.digitalocean.com/community/tutorials/how-to-inst... ). Glad to see people speaking out against it.
- nosir33 11y agoOne example: http://curlpipesh.tumblr.com/ http://curlpipesh.tumblr.com/
- Albright 11y agoThat was the blog I was looking for. Thanks.
- coldtea 11y ago>The problem is that there's a lot of software out there that expects you to install it this way - particularly by piping into sh or bash or the like. The real problem is that this is nothing different than trusting a binary download -- which many more millions (billions) do.
- deleted 11y ago[deleted]
- syntheticnature 11y agoOr, for that matter, a source download. Or one you've hashed (how do you know the hash hasn't been tampered with?), a microprocessor (have you looked at the microcode? the masks), a circuit, etc. Turtles^H^H^H^H^H^H^HTrust all the way down. I'm not being entirely facetious, either, given the advice about disposing of electronics after visiting certain countries.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- geerlingguy 11y agoLuckily both can be installed almost as easily without the curl pipe hack... Not sure why so many projects want to reduce install steps from three to one with a shell script. I could understand if you have 90 steps (in which case I would recommend you figure out a better install process in general), but not for simple 'download something, move it to a path, run a command, and you're done'. See my roles for both of the packages you mentioned above on Ansible Galaxy for more info; I tend to avoid doing the curl pipes for sanity even more so than security. I want to know what I'm doing with my server when I'm installing packages or other software!
- jjuhl 11y agoIf you don't know what it will do. Don't do it. Don't hide behind "I need this and this is how to install it". know what's going on or don't do it.
- vectorjohn 11y agoAlso the ever popular Docker. On the other hand, if it's over SSL, you're just as well off as installing the software any other way. Although, I noticed the Drupal console installer isn't even on SSL.
- voltagex_ 11y agoOn one hand, I'm glad people are working on easier ways to install software. On the other, everyone is ignoring distro package managers. Docker gets it right [1] and then gets it wrong [2] - depends which set of instructions you read. I know creating distro packages and self-hosted repos is difficult, maybe we should be attacking that as a problem instead of writing hundreds of different shell scripts. 1: https://docs.docker.com/engine/installation/ubuntulinux/ https://docs.docker.com/engine/installation/ubuntulinux/ 2: https://docs.docker.com/v1.8/installation/ubuntulinux/#installation https://docs.docker.com/v1.8/installation/ubuntulinux/#insta... Bonus: https://twitter.com/mjg59/status/655812609715769349 https://twitter.com/mjg59/status/655812609715769349