3 ms·
People also curl and execute shell scripts from the internet every day.
by krapht 5y ago
People also curl and execute shell scripts from the internet every day.
- gspr 5y agoYes. And it's a terrible idea.
- handrous 5y agoIt's no worse than several other not-very-secure-but-nonetheless-common ways to install software. Would a MS-provided copy-paste-curl-sh-to-install, say, be any worse than a link to an MSI? Either way I'm trusting that MS isn't sending me ransomware or a rootkit or whatever. If that MSI just executes curl under the hood, exactly like the sh command would have, is it better (nb this is what thin web installers for big programs do, basically)? If I add a PPA for some company and apt-install something from it, unless I audit all the files before proceeding, I'm trusting that they won't format my disk without my wanting them to. How terrible an idea it is depends on who's providing it, same as most other software.
- mappu 5y agoI do agree - There are some specific pitfalls with curl|bash: (A) the web server may serve different code for curl's user-agent than what you audited by clicking the link in a browser, leading to a false sense of security; (B) if the network transfer is interrupted, bash will partially execute an incomplete script; and (C) the recurring prevalence of high-profile bugs like https://github.com/valvesoftware/steam-for-linux/issues/3671 https://github.com/valvesoftware/steam-for-linux/issues/3671 You can mitigate (B) by wrapping the whole script in a function, and you can mitigate (C) with `set -euo pipefail` and `trap`, but that doesn't seem to be the kind of bash scripts that people write in practice. MSI (and deb/rpm) definitely can arbitrary bad things at install time too, but at least their built-in file extraction features are entirely declarative, and they always have an entrypoint for the system uninstaller.