2 ms·
Security is not pass/fail. What threats are enabled by this method? Are there mitigations? Are there alternatives? It would be a mistake to group all curl pipe
by codehusker 10y ago
Security is not pass/fail. What threats are enabled by this method? Are there mitigations? Are there alternatives?
It would be a mistake to group all curl pipes. Does it require elevated privileges? Is it served over TLS? Does it do any signature verification? What the heck does the script actually do?
Different levels of security are required depending on trust. I trust Debian's repository, so I feel less need to audit packages. But a random startup promising ponies? I'd like to at least skim what I can, then throw it in a jail/vm/container to test.
How is curl piping beneficial compared to grabbing the script, giving it a quick read, then executing it? Convenience is all I can come up with, and convenience often seems to be at odds with security.