7 ms·
>Alternatively if you don't trust this approach, you can download the latest release binary Is there a security difference between running a shell script that
by spoonfeeder006 2y ago
>Alternatively if you don't trust this approach, you can download the latest release binary
Is there a security difference between running a shell script that runs a binary vs running a binary directly? Or downloading a executable from the browser vs downloading a shell script using curl?
I get that running the shell script can subjectively look more scary, but doesn't it just basically reveal the inherent danger of running an exe anyhow, assuming there's no code signing keys involved?
- sammy2255 2y agoYou can virus scan a binary before running it
- fire_lake 2y agoAttackers can run a virus scan before distributing it.
- sammy2255 2y agonot sure what you’re getting at
- em-bee 2y agoattackers can check if a virus scan would detect the virus and change it until it passes the scans, so virus scans are not sufficient protection against dedicated attackers. just because a virus scan did not find anything in a binary, that doesn't mean the binary is safe.
- sammy2255 2y agoThats true but no sane malware developer would share their binary with VT. Downloading a binary is still safer than having your shell run arbitrary stuff
- rat87 2y agoSure but then it will trigger false positives some of the time https://github.com/astral-sh/rye/issues/468 https://github.com/astral-sh/rye/issues/468
- sammy2255 2y agoSure but I know a few trusted AVs I look at the results for to know whether this is the case, usually Malwarebytes and ESET, and Kaspersky
- up6w6 2y agoI remember that you can detect the "curl | bash" server side and serve a different script than what the user would get by downloading using other methods[1]. But yeah, the binary itself already has enough attack surface. [1] https://news.ycombinator.com/item?id=34145799 https://news.ycombinator.com/item?id=34145799