4 ms·
> but there is no reason debian packages could not be subject to the same supply chain "evil maid" or upstream "evil new maintainer" I'm always suspicious of t
by robscallsign 6y ago
> but there is no reason debian packages could not be subject to the same supply chain "evil maid" or upstream "evil new maintainer"
I'm always suspicious of the number of blogspam generic linux help advice sites that get you to install some random ppa complete with a nifty little code snippet that automatically installs certs and updates your sources.list! How handy!
- VRay 6y agohaha I love using sites like that for my personal computer/projects, but I never copy and paste code snippets or install PPAs on work machines or computers with magic internet money on them
- ohyeshedid 6y agoBut do you put them on the same networks?
- timemachine 6y ago`curl -o- https://example.com/install-harmless-utility.sh https://example.com/install-harmless-utility.sh | sh`
- stjo 6y agoRelated: Detecting the use of "curl | bash" server side https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b... You can make it so that the server returns benevolent looking code when auditing it with just "curl URL", but return malware when curl is directly piped to bash.
- bscphil 6y agoI.e. the correct and expected method for installing the latest version of Node.js as a package on Debian. (Except you're supposed to run it as root.)
- trickstra 6y agoAnd then there is Raspberry Pi, which recently installed a PPA and gpg key in a kernel post-install hook...