4 ms·
It seems like you're assuming that there's someone vetting these packages. For enterprise distros like Red Hat that's certainly true. Community package maintain
by brianpgordon 7y ago
It seems like you're assuming that there's someone vetting these packages. For enterprise distros like Red Hat that's certainly true. Community package maintainers in, for example, the Debian project provide some safety as well. But there are plenty of package managers where that's just not the case. In the case of Homebrew, the package manager pulls down the program directly from upstream and installs it. It's exactly the same as downloading a tar file from the developer's website over HTTPS. Same with npm. Some package managers like Maven and NuGet will rehost artifacts but if the project owner is malicious or compromised then that won't help - so the risk profile is again basically the same as downloading a tar file from the website.
- paulddraper 7y agonpm removes malware when reported.
- mceachen 7y agos/when/if/ Fixed that for you.
- paulddraper 7y agoI don't believe that changes the meaning.
- mceachen 7y ago(sorry, it was an obscure inverted reference to the saying "not if, but when")
- acdha 7y agoWhich is repeating that sources matter: curl from a source like Github with a solid abuse process is a very different story than an unknown server.
- jsjohnst 7y ago> In the case of Homebrew, the package manager pulls down the program directly from upstream and installs it. Sure, in the most basic case it does this, but even in the most basic case it does more than that. At minimum it also verified the download matches a known good hash. The important part (to me) is that Homebrew also ensures the package installed conforms to Homebrew’s standard. There’s a lot of standards (install in /usr, /usr/local, /opt, etc) on something as simple as where the files are put, let alone how it’s built and it’s dependencies are pulled in. So to say there’s no value in installing from Homebrew over curl|sh is clearly misguided IMHO.
- lloydde 7y agoHomebrew is only as secure as the results of that first curl command /usr/bin/ruby -e "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/master/install)" I get why https://docs.brew.sh/Installation https://docs.brew.sh/Installation doesn’t discuss the versioning or security practices. It is interesting that homebrew doesn’t seem to interface with macOS’s signing and installation practices. Reminds me that there is still no official package manager on macOS. So https://nodejs.org/en/download/ https://nodejs.org/en/download/ has you comparing check sums.
- jsjohnst 7y ago1. Using curl|sh isn’t the only way to install Homebrew 2. Most of my post wasn’t addressing security, but actual real usability gains by using Homebrew.
- brianpgordon 7y agoHow exactly is the file going to get tampered with if you're using curl-to-sh? Everyone uses HTTPS nowadays. Validating the hash is not really doing anything significant. As for ensuring that the package is well-behaved, could you elaborate on that? I'm not aware of Homebrew doing something like chrooting to /usr/local before running the install script. And the install script can do anything as your local user, same as curl-to-sh. Perhaps the Homebrew maintainers would catch something nefarious in the formula itself, but given that most formulas download code from the Internet and run it, that's not much help.
- theamk 7y agoMany package managers provide a real audit trail, and this (IMHO) is very valuable. For example, in python's PIP (and apparently in NPM too), the filenames are never reused: https://github.com/pypa/packaging-problems/issues/74 https://github.com/pypa/packaging-problems/issues/74 Developer's website may change at any time, and even go back-and-forth between good and bad version. The pip software version won't. Put a version pin, and you can be sure you get a good package or an clear error. Granted, you can record/verify the checksum of downloaded files as well, but many people don't. And crazy practices like 'curl | sh' make that impossible anyway.