6 ms·
Gotta love security theater like this: curl --proto '=https' --tlsv1.2 -sSf https://raw.githubusercontent.com/Exein-io/pulsar/main/pulsar-install.sh | sh
by forward1 3y ago
Gotta love security theater like this:
curl --proto '=https' --tlsv1.2 -sSf https://raw.githubusercontent.com/Exein-io/pulsar/main/pulsar-install.sh | sh
So secure, I mean it's forcing https AND tls1.2 - maximum security! Especially when you just pipe a random script into shell.
Also, no information on its authors, who audited the code, what makes it "secure" enough to warrant giving an administrative entitlement over my system. Hard pass.
- deleted 3y ago[deleted]
- codetrotter 3y agoYour comment is confusing because you are quoting from how to install Rust, instead of quoting the OP readme. The OP readme is asking to run a different install script using the same method. curl --proto '=https' --tlsv1.2 -sSf hxxps://raw.githubusercontent.com/Exein-io/pulsar/main/pulsar-install.sh | sh
- SV_BubbleTime 3y agoIs this a joke that I don’t Linux enough to get? That’s the same command with https redacted for some reason.
- figmert 3y agoOP edited their comment.
- codetrotter 3y agoThey edited their comment. When I responded their comment read curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh Which is from https://www.rust-lang.org/tools/install https://www.rust-lang.org/tools/install and therefore was confusing
- figmert 3y agoFair point on the security theatre, but I don't get this: > Also, no information on its authors, who audited the code, what makes it "secure" enough to warrant giving an administrative entitlement over my system. Hard pass. The code is hosted by an organization on GitHub, who have clear links to their website, email, twitter. On their website they have their office addresses and it seems to me that they are registered with the Italian government as a business. They don't mention anything about it being audited or make any claims that it is secure. Both of these would be something to follow up on if someone is planning to use it within their org. I'm not sure what it is you want from them. They've released something, and made it open source. It is a little over a year old, so they're probably still getting their footing and figuring things out.
- forward1 3y agoI want "security" software authors to stop doing harm. Just as physicians take up the Hippocratic Oath, I think we need to set higher standards for programs, applications and processes which avow to improve security, because too often they seem to have the opposite effect. Traditional anti-virus tools are a classic example of this. I do see their website now, but I'm still confused: > We are a team of visioneers, engineers, designers, and security experts backed by top-tier VCs who believe in making security work for everyone. Great. What makes you security experts? In other words, why should we trust you? You say the code is open source and that makes it trustworthy, but source availability is not a panacea. It must really be vigorously stressed, tested and abused by competent hackers (as a consensual contracted service) - again, if we are to call it "security" software. Plainly, this is a beta test for a company that wants to make some money and has generously externalized bugs, issues and other nuances of development unto the open source community, which through some sort of Stockholm Syndrome has actually convinced itself more code - even if it's not good code - is still a good thing.
- insanitybit 3y agoThis is such a ridiculous sentiment. You're blaming these people for Antivirus now? Your whole post is just a nonsensical rant. If you want to say "I'd like to see software like this audited for security" just say so.
- insanitybit 3y agoThat's not security theater at all. It prevents unsafe redirects (--proto='https'), which I've found in the wild exactly because I pass that flag. And specifying a min tls version seems like a good practice in general.
- whalesalad 3y agojust because you got the resource from GitHub successfully and securely doesn’t mean it’s a safe resource to execute.
- lelanthran 3y agoIf you don't trust the installation script to be non-maleware, why are you trusting the binary that the script installs? It's not as if the instructions would allow an attacker to pass you another binary, after all.
- deleted 3y ago[deleted]
- insanitybit 3y agoI didn't say it was. The poster was commenting on the arguments that enforce HTTPS and TLS1.2, and they were wrong - those arguments are not security theater at all. As for 'is curl | sh safe?' I am done arguing with people who don't understand that it's absolutely fine.
- whalesalad 3y agothe poster was not suggesting those things are not legitimate and secure maneuvers ... the poster is suggesting that you can have the most rock solid and authentic transport mechanism and - in spite of that - can still end up compromising your system by running the wrong thing. > As for 'is curl | sh safe?' I am done arguing with people who don't understand that it's absolutely fine. eep.
- supriyo-biswas 3y agoThe curl | bash thing gets talked about so much here, but I wonder who’s stupid enough to not perform their malicious tasks in the binary itself as opposed to the shell script which can be inspected at runtime with `bash -x`.
- wepple 3y agocurl|bash is possibly worse in one minor way; the binary can be dynamically generated or swapped out based on analysis of the target. Downloading directly from GitHub or apt-get is a tiny bit safer in that regard.
- jjnoakes 3y agoI see people rant about this, but not about other equivalent ways of getting scripts from the author to the system and running them. If the instructions were "download, unpack, and run ./configure; make; make install" would you post the same reaction?
- fsociety 3y agoIt’s a fair rant since it is their recommended installation method, and it’s a security project.
- cassianoleal 3y agoNone of this is security theatre. It's ensuring you'll get the exact script they provided and run that to install on your system. It will install something with really high privilege, so if you trust them enough to install that, surely you trust them enough to run their install script. If you can't trust their install script, I'd say you should probably trust them even less with running something in-kernel so none of this is an actual issue.
- TacticalCoder 3y ago> It's ensuring you'll get the exact script they provided and run that to install on your system. Cryptographic signatures can prove that. Curl bash'ing really doesn't. The very few software I install that aren't shipped with Debian (and hence signed and, for the most, also bit-for-bit reproducible btw), I do verify their signature (when they're signed). For that one program I really need that thinks bash curl'ing is somehow as secure as Debian signed (and reproducible) packages (it really isn't) or offers as much guaranteed as a signed software "because https" (it really doesn't), what I do is download the binary myself, take its cryptographic hash, and store that cryptographic hash for later use. So, at least, if I need to reinstall it I know I'm reinstalling the exact same binary I curl bash'ed last time. Curl bash'ing is really a pathetic way to ship software.
- insanitybit 3y ago> Cryptographic signatures can prove that. Assuming you have a fully trusted and bootstrapped side channel to get the public key from. And assuming that the compromise that resulted in this maliciously published binary also didn't compromise the private key. Both are tall orders.
- 77pt77 3y agoIt's missing a sudo.
- deleted 3y ago[deleted]
- c7DJTLrn 3y agoShell security is a joke anyway, there's plenty of other things to be cynical about than an install script. Such as how I can elevate privileges on your machine by phishing your password with a fake sudo binary in $PATH.
- xyst 3y agoProbably a copy and paste from docs for installing rust toolchain https://www.rust-lang.org/tools/install https://www.rust-lang.org/tools/install > curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs https://sh.rustup.rs | sh Sure it’s sketchy, but if you are doing your DD. You are inspecting the script itself. The script itself (https://raw.githubusercontent.com/Exein-io/pulsar/main/pulsar-install.sh https://raw.githubusercontent.com/Exein-io/pulsar/main/pulsa...) doesn’t appear to do anything out of the ordinary. It downloads a few helper scripts to temp directory and installs to /usr/bin. Haven’t looked at the pulsar code yet since on mobile. If you find anything abnormal then yea I wouldn’t install it either. Especially if it needs escalated privileges.