7 ms·
This is sort-of cool, I guess, but also very much not what you would want to do? I mean, people agitate against `curl blah.xyz | sh` for a reason. And this, b
by MarkovChain242 4y ago
This is sort-of cool, I guess, but also very much not what you would want to do?
I mean, people agitate against `curl blah.xyz | sh` for a reason.
And this, by any measure, is much worse. Also: 'By default iPXE does not compile in HTTPS support'
- xen2xen1 4y agoSpace is at a premium on things like that. Having it makes some computers not boot ipxe.
- dsr_ 4y agoThat's why a serious user sets up their own server, serves the images that they have selected and checked, and doesn't serve outside of their known netspace.
- hnlmorg 4y agoI did that for a while but keeping images up to date was a chore I’d often forget to do then regret not doing once I needed it. Sure I could probably automate it with a little effort but instead I switched to this service and have been running with it for a few years now without any issues. While I know there is a risk involved, pragmatically that risk is very low given I’m just an anonymous individual very occasionally using this for personal devices. You can actually run this service locally though. I did contemplate running their Docker container on my home server. However I use it so infrequently that even running their Docker container locally felt like an unnecessary additional piece of work.
- bravetraveler 4y agoI've found it convenient (once setup...) to run internal package mirrors. These with even relatively dated 'netinstall' media can provide you with current installations. Then provide you with super fast updates. I'm more familiar with doing this with RPM based distributions -- CentOS, Fedora, etc. It's basically a web server and rsync behind a [parameterized] systemd timer so you can centrally control existing/new mirrors The results can admittedly be a little funny. If the netinstall is so far behind that RPM doesn't know what to do with the new packages, then yea - time to get a new one :)
- hnlmorg 4y agoThat was the issue for me though. It would often be years between usages since the only time I needed it was when a computer stopped booting or I was repurposing a device. Neither being things that happens very often.
- bravetraveler 4y agoAye, that makes sense. It's hard to justify if you don't leverage it often I moved and I've been hard pressed to bother booting everything up and checking on it, and I have quite a lot of devices to manage
- dsr_ 4y agoThe risk wouldn't be someone deliberately targetting you: the risk would be someone deciding that this is an excellent vector to gain backdoor root access on many random machines.
- hnlmorg 4y agoI wasn’t suggesting I would be personally targetted. I was stating that the infrequency and low criticality of my usage vastly narrows the risk of getting exposed to the attack. Hence my point that if I were using this regularly then I might want to invest in a more secure mirror. But when it can be years between my usages the benefits of self hosting are vastly outweighed but the cost (both in time and electricity) of managing it. Thus I’m willing to take that slight risk in this specific instance.
- gorkish 4y agohttps://netboot.xyz/docs/selfhosting https://netboot.xyz/docs/selfhosting
- rtp4me 4y agoI replaced our legacy PXE boot environment with Netboot, and it made a huge difference. The performance speed from tftp to http is night and day. Plus, you can compile a custom boot image to provide the exact boot environment you need.
- School-Cotton 4y ago> people agitate against `curl blah.xyz | sh` for a reason. What’s the reason, exactly? If you’re principled about only ever installing anything from vetted repos, then sure, your position is at least consistent. But my experience is that people who are appalled by pipe-to-sh are for whatever reason much less appalled by downloading random binaries or .deb files from blah.xyz and running them manually, which seems like just a more labor-intensive version of the same thing.
- hsbauauvhabzb 4y agoCloud services do this to provision hypervisors and other infrastructure, the vms effectively do similar post boot. If you architect your management network well transport security should not be an issue. The ‘piping curl into bash is dangerous’ meme is silly unless you’re actively reviewing shell scripts prior to execution. It’s no different to a git clone, pip install or npm update.
- snvzz 4y agonetboot xyz does signature checking.
- zdw 4y agoMaking it compile with TLS support is really trivial, just an option in a config file: https://github.com/OpenNetworkingFoundation/ipxe-build/blob/master/patches/features.patch#L10 https://github.com/OpenNetworkingFoundation/ipxe-build/blob/... (link is to a repo I worked on that uses Docker to build iPXE with various options enabled, and also embed mTLS certs)