4 ms·
How exactly is the file going to get tampered with if you're using curl-to-sh? Everyone uses HTTPS nowadays. Validating the hash is not really doing anything si
by brianpgordon 7y ago
How exactly is the file going to get tampered with if you're using curl-to-sh? Everyone uses HTTPS nowadays. Validating the hash is not really doing anything significant.
As for ensuring that the package is well-behaved, could you elaborate on that? I'm not aware of Homebrew doing something like chrooting to /usr/local before running the install script. And the install script can do anything as your local user, same as curl-to-sh. Perhaps the Homebrew maintainers would catch something nefarious in the formula itself, but given that most formulas download code from the Internet and run it, that's not much help.
- dickeytk 7y agoThey do chroot. You can only install to specific directories
- brianpgordon 7y agoAh, I found it. On MacOS they rely on sandbox-exec which uses the sandboxing mechanism provided by the kernel: https://github.com/Homebrew/brew/blob/e2c76cce8e01fd80e0910ddbf8d03092d8753673/Library/Homebrew/formula_installer.rb#L930 https://github.com/Homebrew/brew/blob/e2c76cce8e01fd80e0910d... https://github.com/Homebrew/brew/blob/master/Library/Homebrew/sandbox.rb https://github.com/Homebrew/brew/blob/master/Library/Homebre...
- jsjohnst 7y ago> Validating the hash is not really doing anything significant. Yes it is, it’s ensuring that what the maintainer of the formula verified is still what’s being downloaded now. HTTPS does nothing to protect someone modifying the source URL, but the hash does that (assuming the maintainer actually inspected the initial download, which many if not most do). > but given that most formulas download code from the Internet and run it, that's not much help. 1) the previously erroneously dismissed hash helps there. 2) the sandbox which you linked to later also helps too.
- brianpgordon 7y agoI suppose it comes down to whether the Homebrew maintainer who accepts the formula PR containing the hash is actually examining the upstream code in detail. I think that is unlikely; there's too much code for Homebrew maintainers to be experts on everything contained in homebrew-core and follow every single patch. So yes, the hash prevents the upstream project from switching out the code at any time, but if they wanted to add some malicious code all they have to do is file a homebrew-core PR and hide it in a legitimate change.
- jsjohnst 7y ago> I think that is unlikely; there's too much code for Homebrew maintainers to be experts on everything contained in homebrew-core and follow every single patch. By that logic, everything in any package manager should be treated with distrust then. Debian, RHEL, Arch, etc etc. Not saying I disagree with distrusting, just making the point that risk exists everywhere, at some point you have to decide what you’re comfortable with.
- brianpgordon 7y agoTo some extent, sure, but I think that extent is greater with Homebrew. It's my understanding that package maintainers for Debian, RHEL, etc are typically experts in the packages that they maintain. They overlay their own patches to ensure compatibility and submit patches upstream. With Homebrew there's only a small number of committers who maintain the homebrew-core repository, accepting PRs from thousands of people in the community. It's just a different situation.
- jsjohnst 7y ago> It's my understanding that package maintainers for Debian, RHEL, etc are typically experts in the packages that they maintain. That’s certainly true in some cases, but is definitely not the case in the majority. I think you are letting your personal biases color your judgement to much.