3 ms·
Using curl piped to sudo bash can be a security risk, as used to install the demo. # curl -sSL https://get.ondevice.io/|sudo https://get.ondevice.io/|sudo - ba
by neurotech1 9y ago
Using curl piped to sudo bash can be a security risk, as used to install the demo.
# curl -sSL https://get.ondevice.io/|sudo https://get.ondevice.io/|sudo - bash
A fairly balanced post and mitigation options:
https://sandstorm.io/news/2015-09-24-is-curl-bash-insecure-pgp-verified-install https://sandstorm.io/news/2015-09-24-is-curl-bash-insecure-p...
- tomc1985 9y agoI really wish people would stop doing this. It gets tiresome having to check every stupid little install script before running when there is a PERFECTLY GOOD one-liner that does the same damn thing without hiding anything from the user: apt-key add [key]; apt-apt-repository [repo]; apt-get update; apt-get install [program] There: one line, no script-reading BS, and it gets it done!
- kentonv 9y agoYour one-liner only works on Debian-derived Linux distros. Usually the whole point of a curl|bash one-liner is that it works on every Unix-like system.
- tomc1985 9y agoFair enough. I don't know enough about other package managers to know if they can be sequenced like this, but there's nothing wrong with providing another listing like OP with the script link.