3 ms·
Yeah I also noticed the install instructions is run this batch file that gets administrator access and starts downloading things…
by kfarr 2y ago
Yeah I also noticed the install instructions is run this batch file that gets administrator access and starts downloading things…
- gruez 2y agoIt's not any worse than all the projects on github with an "easy" install instructions of "curl ... | sudo sh". Heck, even an innocent "sudo make install" command can easily contain a malicious payload.
- chefandy 2y agoYeah it’s not great but it’s definitely not unusual. And windows reputation-based execution blocking does have false positives. I work for a company that has some very very popular products and some that only see a few dozen downloads per week, and despite being signed, it still takes a while for new versions to build enough rep to not trigger the block.
- tonyedgecombe 2y agoIt's not really the sort of tool that should require admin rights though.
- wutwutwat 2y agoNot to mention a directory full of binaries which could do who knows what. The author is asking people turn off their antivirus, execute their code as admin, and be fine with it running binary files doing whatever https://github.com/abus-aikorea/voice-pro/tree/main/app https://github.com/abus-aikorea/voice-pro/tree/main/app
- 71bw 2y agoIf it requires dependencies, how else do you expect it to work?
- tonyedgecombe 2y agoVendoring.
- elif 2y agoYea not to mention the entire homebrew ecosystem is built around trusting random people's shell scripts. MacOS devs blindly trust it like it's the app store.
- pmarreck 2y agoA simple `brew cat <packagename>` (possibly piping to bat if you want syntax highlighting) should spit out the ruby install formula for that package, for inspection.
- nozzlegear 2y agoThe assumption is that maintainers at Homebrew are reviewing each pull request before being merged, though it's obviously not a full security audit. Homebrew will also use macOS's sandboxing if a formula needs to be built during installation, which will limit file access to specific Homebrew directories and restrict network access. But I agree that everyone should review the Homebrew install script for any package they're installing if they're concerned about security.