4 ms·
> "huh, maybe it's not great my executables are writeable by my account without requiring authorization first" I'm very confused as to what threat model leads
by FiloSottile 4y ago
> "huh, maybe it's not great my executables are writeable by my account without requiring authorization first"
I'm very confused as to what threat model leads to this concern on an unsandboxed (predominantly) single-user desktop OS such as macOS.
- still_grokking 4y agohttps://xkcd.com/1200/ https://xkcd.com/1200/
- FullyFunctional 4y agoThat's exactly it, except it's worse in that every time you run an application, you are essentially letting the code author do anything as you on your machine (obvious, but worth stating). The only reason this works is because we trust "people" to discover this and fix it (and it will usually have consequences for the perpetrator). I'm just not sure this model works anymore, just like we don't use telnet, rcp, and all the other things that assumed you could trust the network.
- mdaniel 4y agoI would guess the same risk as "npm i" or "pip install": exfiltration of credentials or other supply chain attacks. My greatest threat is not a bitcoin miner but rather taking advantage of the data on my machine that I'd rather not leave my machine
- acdha 4y agoThis is orthogonal to that point: if I can run code as you, I can exfiltrate your data or write an exploit anywhere writable. The only case where having Homebrew be read-only matters is on a multiuser system where you can do something as a non-admin user.
- pxc 4y agoYou're not wrong about the way macOS is typically used, but... I love that the things people will say about macOS include both 'certified Unix' and 'single-user OS'.