7 ms·
Attacks like this are not helped by the increasingly-common "curl | bash" installation instructions (e.g. the new "native" Claude Code install)... Publish thro
by emilecantin 8mo ago
Attacks like this are not helped by the increasingly-common "curl | bash" installation instructions (e.g. the new "native" Claude Code install)...
Publish through homebrew like a civilized person, please!
- isodev 8mo agoAnd donate to Homebrew, like a civilised person
- what 8mo agoAs if homebrew is any more secure. The only reason to use homebrew is convenience.
- retired 8mo agoHomebrew also installs through curl | bash but since recent they also offer a .pkg installer.
- krackers 8mo agoThat wouldn't really help, it could be more naughty and use pastejacking so you don't even realize what's happening. That might end up catching a lot of people because as far as i know by default bash doesn't use bracketed paste, so you think you're copying a real command and it ends up sending your secrets before you know what happened. Disabling JS + bracketed paste seems to be the only good solution. Btw OP article uses a weird setup, why would they use `bash -c "$(curl $(echo qux | base64))"` instead of just "curl | bash"
- donatj 8mo agoA homebrew tap is really a lateral move from a safety perspective and still usually invoked by pasting into the command line.
- skybrian 8mo agoI will never use Homebrew again because I'm still sore that they dropped support for a Mac OS version that I was still using and couldn't upgrade because Apple didn't support my hardware anymore. Any decent project should have a way to install without Homebrew. It's really not necessary.
- wookmaster 8mo agoSeems reasonable to not support an OS apple doesn’t support anymore
- nonethewiser 8mo agoApple only supports for 3 years
- post-it 8mo agoWhich device was only supported for three years? Even the final Intel Macs are getting six.
- einr 8mo agoMore than six. 2019/2020 Intel Macs get Tahoe 26.0 + about three years of security patches for Tahoe. The last Intel Mac will be out of support in probably late 2028.
- pdimitar 8mo agoWell, my iMac Pro is not getting Tahoe. That's an Intel Mac. No idea why they figured that's their line in the sand.
- einr 8mo agoThe iMac Pro is a 2017 computer, although it was sold until 2021. So given that it runs Sequoia, that's anywhere from six to ten years of OS support. OCLP will probably figure out how to patch Tahoe for the iMac Pro soon enough, but until then, you can rejoice in the fact that you don't have to run Tahoe. It could be worse -- at least you didn't spend tens of thousands on a 2019 model Intel Mac Pro in 2023. (Yes, they still sold them, and owners of those will be SOL in 2028. That's probably the worst OS support story in recent Apple history, and it's for some of their most expensive machines)
- fouc 8mo agoI wish mac users would stop using homebrew and use a real package manager with actual dependency management. At the very least, replace homebrew with something like devbox which has `devbox global` for globally managing packages, it uses nix under the hood, and it's probably the simplest most direct replacement for homebrew.
- AnonC 8mo agoI use MacPorts because of older versions of Homebrew having a weird and insecure design. [1] I think some of those design issues may have been fixed, but I’m wary of Homebrew. [1]: https://saagarjha.com/blog/2019/04/26/thoughts-on-macos-package-managers/ https://saagarjha.com/blog/2019/04/26/thoughts-on-macos-pack...
- pram 8mo agoI don't agree this is an issue and I'll tell you why: Homebrew isn't responsible for keeping the system functional like apt or pacman, it's a supplemental thing. I've also found it's useful in this capacity on Linux specifically with LTS distros, I can get the latest fzf or zoxide or whatever without having to add some shady repo.
- thewebguyd 8mo agoThis is how I see/use brew as well, and being able to just blow the directory away anytime and start over if need be is nice. It's not a "system" package manager, nor was it ever meant to be. Its supplemental. I've also found it valuable on the various immutable linux distros.
- TheDong 8mo agoI wish the mac users would switch to a real OS, linux, so that software companies would release linux versions of stuff first. Codex, Claude Desktop, etc etc all starting out as "macOS exclusive" feels so silly when they're targeting programmers. Linux is the only OS a programmer can actually patch and contribute to, and yet somehow we've got a huge number of developers who don't care about having a good package manager, don't care about being able to modify their kernel, don't care about their freedom to access and edit the code of the software they rely on to work... It's depressing how much of the software industry is just people on macbooks using homebrew to install a newer version of bash and paying $5 for "magnet" to snap windows to the corners since their OS holds them in a prison where they can't simply build themselves a tiling window manager in a weekend. The OS is core to your tools and workflows, and using macOS cedes your right to understand, edit, and improve your OS and workflows to a company that is actively hostile to open source, and more and more hostile to users (with a significant increase in ads and overly priced paid services over the years). Anyway, yeah, homebrew sucks. At least nix works on macOS now so there's an okay package manager there, but frankly support for macOS has been a huge drag of resources on the nix ecosystem, and I wish macOS would die off in the programming ecosystem so nix could ditch it.
- bugbuddy 8mo agoMeanwhile, homebrew install instructions: /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh https://raw.githubusercontent.com/Homebrew/install/HEAD/inst...)" Then it prompts user for admin previledges. Also, it does not support installing as a local non-admin user.
- rvz 8mo agoI would agree if it was the only way to install Homebrew, but it is not. You can install it via a .pkg here: [0] [0] https://github.com/Homebrew/brew/releases/tag/5.0.13 https://github.com/Homebrew/brew/releases/tag/5.0.13
- brigandish 8mo agoDoes it still do the "you can't install via sudo, that's a security risk" while not allowing a non-admin install? I laugh and I cry. Why does anyone trust that project to understand security?
- marxisttemp 8mo agoMacPorts, of course, features an actual .pkg installer, as well as doing pretty much everything else better, and having more packages, and existing first.
- radicality 8mo agoI use brew but willing to try out Macports. How come the package install instructions seem to require sudo under macports? Does that not carry more risk during the install ?
- marxisttemp 8mo agoBecause it requires access to /opt/local. It drops down to the macports user for all the actual fetching and management.
- gchamonlive 8mo agoMaybe tools like https://github.com/vet-run/vet https://github.com/vet-run/vet could help with these projects that would rather you use their custom install script instead of complying to distro-specific supply chains.
- root_axis 8mo agoIt's not really any different than downloading a binary from a website, which we've been doing for 30 years. Ultimately, it all comes down to trusting the source.
- idle_zealot 8mo agoWhich is why package managers with well-maintained repositories are the civilized solution to software disruption. Unfortunately the Linux world has been dedicating a lot of energy to making Windows-style "download and run the exe" possible on Linux.
- nubinetwork 8mo agoI've heard this time and time again from new Linux users: "I don't want to learn the command line, I just want to be able to install and run whatever I want"
- kalaksi 8mo agoYou don't need command line for installing packages, though
- nubinetwork 8mo agoDoesn't matter, they'll need to use it eventually for something, freak out, and go back to windows.
- gruez 8mo ago>Which is why package managers with well-maintained repositories are the civilized solution to software disruption. How does that model work with distros like debian, where they freeze package versions and you might not get claude code until 2027 (or whenever the next release is)?
- TheDong 8mo agoIf the debian maintainers don't align with your preferences you can: 1. Create your own apt repository with newer software, and install from that. It's easy to package things, you can share the repository with trusted friends, running linux with friends is fun. 2. You can switch to a distro, like NixOS or Arch, which values up-to-date software more than slow stable updates. Debian does seem to be more aligned with mailservers and such, where updates can be slow and thoughtful, not as much with personal ai development boxes where you want the hot new ai tool of the week available asap. ... Either way, learning to package software correctly for your distro of choice is a good idea, it's fun to bang out a nix expression or debian package when you need to install something that's not available yet.
- sfbapt 8mo agoWhat's the security benefits of using homebrew? Isn't it just another layer of redirection before downloading the software?
- TheDong 8mo agoThere are some real differences. All the homebrew packages have checksums and are versioned in git, so if the upstream website is compromised and a malware installer is put in place of the package, `curl | bash` will just install the malware, while `brew` would start erroring out and refuse to install after downloading something with a different checksum. You also get an audit log in the form of the git repo, and you also ensure everyone's downloading the same file, since `curl | bash` could serve different scripts to different IPs or user-agents. I don't think brew does proper build sandboxing, so like `./configure.sh` could still download some random thing from the internet that could change, so it's only a bit better. If you want proper sandboxing and thus even more security, consider nix.
- steve1977 8mo agoA civilized person of course would use either MacPorts or a proper native macOS installer package.
- TheDong 8mo agoCivilization is about cooperating with your fellow man to build great things, not bowing to the feudal lord Apple Inc. A truly civilized person would use Linux, OpenBSD, etc, a free operating system where they may contribute fixes for their fellow man without having to beg at the boots of the single richest company on the planet with radar numbers asking for fixes from on high.
- robin_reala 8mo agoApple are just number two, half a trillion behind nVidia. Hopefully that’ll soon change when the bubble pops.
- steve1977 8mo agoProjects like MacPorts and Homebrew are trying to bring at least some freedom into the macOS fiefdom. I'm just saying MacPorts is the better of those two.
- tacker2000 8mo agoI agree about the proliferance of curl | bash, but homebrew is not the answer. They cut support for old platforms way to fast and just in essence try to dictate far too much.