8 ms·
"best practices" `curl https://pyenv.run https://pyenv.run | bash` hmmm...
by wwwhizz 5y ago
"best practices"
`curl https://pyenv.run https://pyenv.run | bash`
hmmm...
- maccard 5y agoWhat's the problem here? The script is served over https, so it's not going to be tanpwred with (unless you have a malicious cert, but at that point you can't trust anyone), and curl | bash isn't any worse than downloading a script and just running it, or running a precompiled binary you don't trust.
- Cthulhu_ 5y agoThe request itself won't be tampered with, but what if the host was? That endpoint could be compromised and send you a different script. They should offer a download with signature validation instead. Signed by Apple, Microsoft, etc if possible.
- maccard 5y agoIf you're afraid the host may be untrusted then you would be wrong to download any of their code at all. The safety is in reviewing the code there, not in avoiding curl | bash. Running pip install or npm install is just as dangerous. > They should offer a download with signature validation instead. Signed by Apple, Microsoft, etc if possible. If the host is compromised, the attacker will just get Microsoft to sign their malware instead; see [0]. If the host is compromised, and you run the code without reviwing it, you're hosed regardless. [0] https://arstechnica.com/gadgets/2021/06/microsoft-digitally-signs-malicious-rootkit-driver/ https://arstechnica.com/gadgets/2021/06/microsoft-digitally-...
- dragonwriter 5y ago> The request itself won't be tampered with, but what if the host was? What if your distro package repository was?
- doix 5y agopyenv could get taken over and you won't know. It's also possible to detect when someone is piping to bash (on the server) and serve a different payload [0]. You're better off piping curl to a file, reviewing the file and then running it manually. [0]: https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- nerdponx 5y agoYou often want to do this anyway, because the installer often supports various options and env vars. If you download the file you can read its --help output, and even keep it on hand in case something bad happens, or just for your own records.
- maccard 5y ago> its also possible to detect when someone is piping to bash (on the server) and serve a different payload. If you have a fear of your source maliciously serving you different code over curl, don't run their code at all. > You're better off piping curl to a file, reviewing the file and then running it manually. Right, but the safety there is reviewing the code. Running brew install, npm install, pip install, or a binary could all run malicious code too.
- KronisLV 5y agoShouldn't there be some CLI tool that would allow verifying the checksum of the file as an intermediate step? Something along the lines of: curl https://pyenv.run | pass_on_through_sdtout_if_hash_matches md5 8bffaf30c9ba21393329d531063056fe | bash That way, someone who validates the file locally, can be sure that what's piped is the same thing.
- maccard 5y agoYes, there absolutely should be. It would be a massive improvement if that happened. It requires a few extra steps to be actually secure. You actually need to verify the hash from a trusted source for it to be actually secure. If the delivery has been tampered with, you need to ensure that the delivery of the hash has also not been tampered with. In practice, codesigning is the solution, but certs are expensive, and impractical for a small project.
- jayknight 5y agoIt's also possible for you to copy things you can't see from web pages. So the command(s) you end up with may not be what you thought. So there's a trust issue with the site you get instructions from ass well. See http://thejh.net/misc/website-terminal-copy-paste http://thejh.net/misc/website-terminal-copy-paste
- nxpnsv 5y agoWell I do `brew install pyenv`, but honestly I am not sure that is much safer...
- rbanffy 5y agoI think it'll compile various Pythons on your machine under your user. I'd prefer to install (learned this today) with Homebrew multiple versions (not sure how possible it is) as `brew install python@3.6 python@3.7 python@3.9` (because Big Sur has 3.8 built-in). In reality, I'm a more traditional Unix person and prefer MacPorts, where you can do `sudo port install python36 python37 python39` in a very BSD way of doing things. Homebrew has broken my computer one time too many.
- ktm8 5y agoThe script itself is also a wrapper for curl | bash
- lvncelot 5y agoIt's curl | bash all the way down.
- bananabiscuit 5y agoIs this much worse than downloading some installer and running it? Those can be just as compromised. So can packages in package managers for that matter.
- kim0 5y agoExactly! At least I can read the script but not the binary!!
- jen20 5y agoPerhaps… [1]. [1]: https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- rbanffy 5y agoThat's why the traditional Windows way of downloading a setup.exe and running it with admin privileges is a bit scary for people coming from other platforms. Installing an .msi is less bad, or so we are taught.
- e12e 5y agoDepends. On windows an installer might be signed. On Linux a package should be signed. You can't know that curl and your browser get the same data - but you can for example split it up: curl https://pyenv.run -o install.sh #examine install.sh bash install.sh Ed: or just "save as" like with an installer. Piping straight to bash can be especially bad if you've cached sudo credentials for the current session - some of these scripts call sudo "inside". Otoh - the connection is signed (it's https)-unfortunately it's often quite easy to compromise a web site. Obviously, listing gpg signatures on the same page doesn't add much unless it's possible to verify the gpg key some other way. Ed: another problem is that you really should check exactly what's in you clipboard before pasting to a terminal.
- maccard 5y agoThe safety in your steps is reading the script, not in avoiding curl | bash. An installer being signed doesn't guarantee it's not malcious; if someone has overtaken a host and replaced the binaries, they'll just sign them themselves. Unless you're manually inspecting the signature matches your expected source, running a signed binary doesn't save you.