3 ms·
> curl is mature enough that the chance of an impactful bug is basically zero Curl is also something that should be thoroughly sandboxed to begin with, because
by swiftcoder 4mo ago
> curl is mature enough that the chance of an impactful bug is basically zero
Curl is also something that should be thoroughly sandboxed to begin with, because even if there are no vulnerabilities in curl itself, its a tool for downloading arbitrary data over the internet, and you may well accidentally trigger vulnerabilities in every other part of your environment just by downloading arbitrary data to your shell...
- inigyou 4mo agocurl is the sandbox. It exchanges packets with the internet and then outputs a safely sanitized byte stream.
- swiftcoder 4mo agocurl is only the sandbox if you don't then do anything with the byte stream. Pipe it to bash? game over Pipe it to less/more? Better hope your distro keeps those patched Open the file in a browser or PDF reader? Hey, look at all this shiny new attack surface!
- layer8 4mo agoHow do you set up the sandbox without having downloaded anything from the internet? I guess there’s still places where you can buy Linux CDs.
- inigyou 4mo agoWell yeah, that's true for any sandbox. If you pipe stuff outside of the sandbox, outside of any sandbox, and run it there, then you're not running it in a sandbox.
- swiftcoder 4mo agoRight, but nobody actually uses curl as the end destination, right? You use it to download something so that you can run another tool on it. And as such, you need to already be sandboxing the tool (since it processes untrusted data you received over the internet).
- inigyou 4mo agoHow would sandboxing curl help with vulnerabilities in your pdf reader?
- swiftcoder 4mo agoObviously, you need to sandbox all tools in the chain that handles untrusted data. This is security 101 stuff
- inigyou 4mo agoDo you sandbox the sandbox? When do you stop?
- niij 4mo agocurl is not anti-virus.