4 ms·
Yeah I think everyone feels icky about 'curl https:// https://.. | sh' but to what degree is doing so any more insecure than other "normalized" software distrib
by doesnotexist 5y ago
Yeah I think everyone feels icky about 'curl https:// https://.. | sh' but to what degree is doing so any more insecure than other "normalized" software distribution practices?
See also:
https://twitter.com/moyix/status/1451318133021675520 https://twitter.com/moyix/status/1451318133021675520
- jeffbee 5y agoYou can check for this vulnerability using the existing tooling any k8s admin already has on their systems by necessity. It's always foolish to install unknown software and security professionals should never advise that.
- tbrownaw 5y ago> unknown software Looking at the blog URL and header bar, and the script URL, this is pretty clearly a company blog recommending to use the company's own product. I hardly think that context counts as "unknown".
- justinclift 5y agoLets say (for example) that was published on a wordpress site, and the admins for whatever reason didn't secure it properly. The article in question which _today_ looks all legit and points to a nice working script, might tomorrow be pointing to someone else's script that's a lot less legit. And yes, in this imaginary scenario that wordpress install leads to a host of other problems for the company. No need to make them your problems too though. ;)