3 ms·
One of the big problems is that no one actually does read these scripts. You could say "Oh but it's their own fault, duh" but theres a very legitimate argument
by Systemerror7A69 1mo ago
One of the big problems is that no one actually does read these scripts. You could say "Oh but it's their own fault, duh" but theres a very legitimate argument to be made users going the path of least resistance and that you shouldn't offload this responsibility on your users.
Regarding appImage or rpm, attackers need to build and package these to inject these, while this curl | bash pipe opens up the possiblity of payloads simply by taking over the domain. And this isn't really that far fetched, just think about the Notepad++ update payload recently. The regular package was unaffected while the domain used for the update was taken over.
Then theres also the argument about normalization. Just like he said, this isn't just something he said, this is a very real argument. You don't want to teach users bad habits. Even if / you / inspect the code you get, not everyone will. And ultimately, we should strive to make the Internet a safer place, if only to get less botnets.
- indstinctdialog 1mo agoThis is the same as terms of service agreements. There's a crowd mentality around it where only one person with enough of a voice needs to read it and scream. It's brittle because if everyone thinks that then nobody checks it but the probability scales with the attention it gets. Totally agree we should make the internet safer, this is just a clarification that we don't necessarily need everyone to check it. One person who always checks everything and sends this to their LLM and posts a viral post can be a deterrent. The installer is one threat. You're then running this on your machine which is the next threat.
- walrus01 1mo ago> You don't want to teach users bad habits. Take a look at the screenshots here for one example of getting non-technical users to paste things into the equivalent of bash: https://www.tilburguniversity.edu/about/conduct-and-integrity/privacy-and-security/fake-captchas https://www.tilburguniversity.edu/about/conduct-and-integrit...
- b5n 1mo ago> no one actually does read these scripts I do.