3 ms·
> One cannot simply obtain a cert from a trusted CA. One can't simply MITM a datacenter. > literally nobody can trust the internet. Hence why CA's exist lol
by Nyr 11y ago
> One cannot simply obtain a cert from a trusted CA.
One can't simply MITM a datacenter.
> literally nobody can trust the internet. Hence why CA's exist
lol
> it's something that is already supported by Github but you are intentionally breaking
I'm not breaking anything. It is supported by GitHub but not by many of the client machines (by default).
> It's called "social engineering" and actually quite a comment method of attack.
I unfortunately can't fix user stupidity.
> That's an edge case.
That's when you've proved you have no idea about what my user base is. Minimal images are very common for OpenVZ templates.
Anyway, and to end this: you've already stated your points and I've given you my explanations. You can either accept them or not, but I don't want to waste more time on this - feel free to fork if you don't like it.
- laumars 11y ago> One can't simply MITM a datacenter. SSHing onto a Linux server in some secure datacentre doesn't magically mean that everything that server connects to outside of the datacentre is also going to be secure. I assume that you do actually understand how the internet works? :p > I'm not breaking anything. It is supported by GitHub but not by many of the client machines (by default). Of course you're breaking things. You're breaking the security of HTTPS by disabling cert checking. And you're breaking readability of your install code by using URL shorteners. As for HTTPS not being supported by many of your client machines by default, it's so very easy to rectify: $(which apt-get yum) install ca-certificates This will work on Debian and its derivatives as well as the usual Redhat derivatives too. So that one line and works on all your supported platforms. It really is that simple. :) > I unfortunately can't fix user stupidity. But you're forcing user stupidity by using stupid defaults. It's quite literally your fault that they're being stupid as you're recommending they do stupid things. > That's when you've proved you have no idea about what my user base is. Minimal images are very common for OpenVZ templates. I happen run a hosting as a side project and almost exclusively use OS containers for personal projects. So I'm well versed in these kinds of containers and the kind of users you're targeting. You're just making excuses for bad security practices. > Anyway, and to end this: you've already stated your points and I've given you my explanations. You've given excuses, not explanations. I've demonstrated how easy it is to work around the limitations you've put in place. You've just given lazy excuses as to why you couldn't be bothered. The crux of the matter is when building gateways you should NEVER default to insecure settings like you are currently doing. Period. > feel free to fork if you don't like it. To be quite honest, it could benefit from a complete rewrite. The code is functional but messy, your OS detection could use a little fine tuning too. But the real problem is that there's more instances within your script of code getting pulled from the internet with certificate checking disabled, and that would also need to be fixed (but at least you're not using URL shorteners there). Your intentions are noble, but sadly your execution is less so. Which is what happens when you never listen to advice. And looking at the comments on your repo, this has been an issue that has been raised a multitude of times before. So it's not just me being an elitist :)
- Nyr 11y ago> The code is functional but messy, your OS detection could use a little fine tuning too. Feel free to submit a pull request if you can improve OS detection, it certainly is primitive. > But the real problem is that there's more instances within your script of code getting pulled from the internet with certificate checking disabled I have just pushed a commit with a better approach.