7 ms·
Also, no one’s forcing you to pipe curl into sudo sh. I don’t think a software project listing this as an installation method is that big of a red flag to be ho
by bryancoxwell 3y ago
Also, no one’s forcing you to pipe curl into sudo sh. I don’t think a software project listing this as an installation method is that big of a red flag to be honest.
- op00to 3y agoI’ve … never piped curl for home assistant.
- hk1337 3y agoYeah, you could always just curl it first and see what it’s going to do.
- posnet 3y agoIt can be detected if your adversaries are clever enough: https://lukespademan.com/blog/the-dangers-of-curlbash/ https://lukespademan.com/blog/the-dangers-of-curlbash/
- thinkmassive 3y agoCongrats, you just defeated the attack by manually downloading the script before running it!
- post- 3y agoTbh, I’m put on more on alert by the spelling errors in the linked post than I am by the ostensible threat of a server timing my requests in order to serve malware. It’s good practice to check anything that you’ll pipe to `sudo`, but this article’s level of paranoia is kind of self-defeating, no? At some point, we all trust the things we run on our machines. We rely on communities — and our participation in them — to vet installations. There is no perfect solution. Someone will always be misled.
- jrockway 3y agoWhy is "sudo" emphasized so heavily, anyway? Running as your ordinary user, that shell script can send someone your session cookies, authenticate with your SSH agent, and really anything that you can do. Sure, maybe not running as root protects the integrity of the OS and prevents some persistent keylogging attacks, but honestly... you don't need a keylogger when you just grab the cookies, or install your own binaries farther up in the path (good old ~/.local/bin/firefox instead of /usr/bin/firefox). Frankly, being anything other than super paranoid is almost a little reckless. Also, shit-talking Home Assistant is a pretty weird take. I wouldn't write it in Python configured half in YAML and half in SQLite either, but ... not having to write it myself was the fun part.
- bombcar 3y agoThis is basically https://xkcd.com/1200/ https://xkcd.com/1200/ Anyone who really complains about curl | sudo is just doing it for nerd points, because I guarantee you they happily install all sorts of other software without "vetting" it. And if someone caught someone doing trickery it'd be big news.
- tmpX7dMeXU 3y agoYup. It’s very “fake nerd” energy.
- spiderxxxx 3y agoThere are those of us who are security minded and will in fact download the script and check the sha1/sha256 and review the script before running it. Any time I see this curl sudo thing is when there's always another (manual) option. The shell scripts themselves aren't so complex that you can't figure out what they're doing, they're normally fairly straightforward, unless they were generated by some tool, or are in fact malware, so you can see if something looks funky before you run it. Sure, there can be a malware that makes it so you can't tell, but normally not.