4 ms·
My worry with brew and literally any software installed from "random" sources is that I don't want to trust it, but it runs with all my credentials and can do
by FullyFunctional 4y ago
My worry with brew and literally any software installed from "random" sources is that I don't want to trust it, but it runs with all my credentials and can do just about anything on my behalf. When using, say, macOS or Ubuntu, I have made the deliberate decision to trust the vendor to not be subversive, but as soon as you bring in outside sources you expose yourself. This isn't an academic concern, Log4J and the ongoing phishing attacks on PyPI are good reminders.
Apple at least seems to be taking it seriously and has started requiring explicit authorization to access various locations (like Photos), but treats the shell as single security domain, so it's (AFAICT) a global setting for brew installed binaries. For Linux I don't know of anything similar.
Obviously there are many things one can do but it needs to be the default and it needs to be not so inconvenient that people just turns it off (hello Microsoft Vista's UAC).
What are the solutions here?
- kdtsh 4y agoSELinux or AppArmor provide MAC if that’s what you’re looking for.