5 ms·
> curl ... | python Ah goddamnit. 868 lines, including os.rmtree calls and stuff. Also installable via pip, but... "not recommended", and: [RuntimeError
by memorysafety 7y ago
> curl ... | python
Ah goddamnit.
868 lines, including os.rmtree calls and stuff.
Also installable via pip, but... "not recommended", and:
[RuntimeError]
Poetry was not installed with the recommended installer.
Cannot update automatically.
- StavrosK 7y agoYeah, I hate this trend. Unfortunately, you can't pip install poetry because it needs to manage packages, so I guess a different way was necessary. Still, OS-specific packages would be nice, I guess they just need volunteers.
- heavenlyblue 7y agoEven pip is pip-installable. What makes poetry any different?
- acdha 7y agoIt’s running over HTTPS from an auditable source. Is that _really_ so much worse than a pip install, and can you explain in detail why you believe that to be true?
- chrisfinazzo 7y agoSomewhere, I can hear John Siracusa saying, 'curl piped into a shell? No thanks.'
- acdha 7y agoYes, funny, but seriously, where's the threat model where you've analyzed the risks of installing code from GitHub over HTTPS and found it to be less secure?
- chrisfinazzo 7y agoTo be clear, either of these methods can have problems, it's not unique to curl and your shell of choice. Some of the better open source projects will say up front that if you are concerned about this kind of thing, feel free to read the installer script and decide for yourself if everything's kosher.
- acdha 7y agoYes, my point was that if you're worried about running someone else's code the answer is to audit that code rather than the transport layer. There are valid concerns with HTTP or in scenarios where something could be targeted to a single user, but neither of those are relevant to 99% of the time people raise this complaint.
- dTal 7y agoThere's always the risk that the script will fail to completely download and leave your system in a broken state. This can be mitigated against by the script authors by wrapping everything in a function which is called on the last line, but how do you know they've done that without downloading the script and checking first? (Poetry have done this, for what it's worth)
- MiroF 7y agoit's pretty easy to detect only when you are being piped and then only include malicious code then
- acdha 7y agoDo you believe GitHub has that infrastructure deployed? If not, this is a blind alley to worry about. If so, what other precautions have you taken to avoid compromised tarballs, unauthorized pushes to repos with auto-deployment pipelines, etc.? The point is that in reality you’re orders of magnitude more likely to be compromised by ads in your browser, an undetected flaw in legitimate code, or a compromised maintainer than GitHub having deployed custom infrastructure to target you. If you’re being target by a government, why would they do this instead of using the same TLS exploit to serve you a dodgy Chrome or OS update which is harder to detect and will work against 100% of targets?
- tekknik 7y agoSo because ads can compromise us we should ignore the security of package managers? How about this for a reason, where are the checksums when I’m curling and piping? How do I validate in an automated fashion the validity of this file I’m piping into an interpreter? When installing a package it’s quite easy to have redundant copies of an index with checksums pointing to a repository hosting the actual code. The attack surface is much smaller vs a curl | python This is bad practice, stop promoting it or downplaying it’s security issues. Edit: smaller instead of larger
- acdha 7y agoHTTPS has checksums, and note that we’re specifically talking about installing from Github, where every change is tracked. > This is bad practice, stop promoting it or downplaying it’s security issues. I’m trying to get you to do some security analysis focused on threats which are possible in this model but not the real alternatives (download and install, install from a registry like PyPI or NPM, etc.). So far we have “GitHub could choose to destroy their business”, which seems like an acceptable risk and about the same as “NPM could destroy their business”.
- linsomniac 7y agoI teach my kids to use the right tool for the job, because using the wrong tool for the job can lead to injuries. But I violate this all the time, myself. It's just a good habit to get into. "curl | bash" is a bad habit to get into. It works under certain circumstances, like making sure it's an SSL connection from a source you trust. But it's just a bad habit for the average person to get into.
- tomp 7y agoWait, are you seriously complaining about executing code you downloaded from the internet, that installs a package manager - i.e. a piece of software that downloads executable code from the internet?!
- figgis 7y agoNot the OP but I am very concerned with telling people to pipe anything from curl straight to your shell.
- snorremd 7y agoI think what the comment you are replying to are getting at is the fact that installing pip packages from the Internet and importing them in your python app is not that different from piping code from the Internet into your python executable. In both cases python code from the Internet will be executed with your user privileges from within Python. Unless you audit every python package you consume, you might as well accept a curl https://example.com https://example.com | python installer too. It is not that long ago that PyPI hosted malicious (typo-squatting) packages: https://news.ycombinator.com/item?id=15256121 https://news.ycombinator.com/item?id=15256121
- Sean1708 7y ago> Also installable via pip, but... "not recommended", and: If you install it via pip you need to update it via pip, the alternative would be insane. And the reason it's not recommended is that it doesn't let you use multiple Python versions, but if you're only using one version then installing by pip works fine.
- meowface 7y agoThey could just as easily add the same code to setup.py, and then pip would run it as soon as you run pip install. There's generally no security difference between curl | python and pip install.