3 ms·
What's a better alternative?
by ksrm 10y ago
What's a better alternative?
- coherentpony 10y agoDownload it, audit the code, and then do python shellshare
- cperciva 10y agoAs viraptor said, putting code into a public repository (e.g., debian packages); that way there should be a paper trail if the code is modified. Beyond that, there's a simple matter of advertising: "Share your terminal (read-only)" may mislead some people about what is happening. A more accurate description would be "Give us control of your terminal (we promise we'll only let other people read it, not write anything)".
- emodendroket 10y agoImagine if this principle were applied to other software products. "Click here to download the Office installer, which will gain full admin-level access to your machine. We promise to only use that to install Office."
- cperciva 10y agoThat would be awesome. Users might start to understand security.
- emodendroket 10y agoUsers don't read.
- vitorbaptistaa 10y agoAs usual, you can never be sure unless you read the code, luckily, it's very small: https://github.com/vitorbaptista/shellshare/blob/master/public/bin/shellshare https://github.com/vitorbaptista/shellshare/blob/master/publ... The only thing sent to shellshare's servers is the text in your bash terminal. There's no return channel for the servers to send commands back to the computer. You could argue that you're giving control of the terminal because you're running a third-party executable, but that's the same for any executable you run.
- mappum 10y agoYou could use hashpipe (https://github.com/jbenet/hashpipe https://github.com/jbenet/hashpipe), from Juan Benet (the author of IPFS). It simply checks that the input to the command matches a given hash, so you can do `curl <url> | hashpipe <hash> | sh`, and if the output of the curl command is different than expected it won't be passed in to `sh`.
- eriknstr 10y agoIronically the prebuilt binaries of hashpipe itself are provided without means of verification :I So if you are going to use hashpipe, I think you should download it in source form, read it -- it's under 100 SLOC -- and then build it from source yourself. This way, you do that once and then in the future provided that you trust those sending you various scripts and binaries and the channel they used to provide the hash, all is well and no further manual verification is needed on your side of things ever again for any of those.
- dbdr 10y agoIf an attacker can modify the output of the curl command (on the host or on the wire), cannot they also modify the value of the hash seen and copy-pasted by the end-user? I must be missing something...
- deleted 10y ago[deleted]