3 ms·
Wouldn't the obvious solution be to throw a captcha in-front of the download? Or am I missing the fact that this exact download path needs to be directly acces
by Robadob 11y ago
Wouldn't the obvious solution be to throw a captcha in-front of the download?
Or am I missing the fact that this exact download path needs to be directly accessible by package managers or something?
- ch0wn 11y agoAutomated downloads don't have to be malicious. I'm sure there are tons of legitimate scripts out there that fetch curl via those URLs.
- Robadob 11y agoThe fact the article states they've already changed the url for downloading the file, suggested to me that it wasn't intended to be automatically downloaded (I realise that automation does not imply malicious).
- rogeryu 11y agoThere is no front-end. Curl downloads similar to a commandline script. If necessary it can handle logins, but a (graphical) captcha won't work.
- nkozyra 11y agoAre you talking about how cURL works or how one downloads (Windows) cURL in the first place, as is the topic of this post? It may not be ideal but you could certainly put some form of authentication in front of the Windows downloads or force token generation via the Web site to download the executable. The question is whether that's a good idea - as mentioned, it's not cURL's responsibility to prevent malicious usage, but perhaps being a little more cautious about the acquisition of cURL in the first place for Windows users might not be seen as an intrusion.
- swiley 11y agoCaptcha'd downloads are the worst: no restarting, no automation, no direct linking.