6 ms·
This is one of my pet peeves of late - so many tools and tutorials advise the user to curl and pipe some script of the net to install and make it work. Why aren
by static_typed 14y ago
This is one of my pet peeves of late - so many tools and tutorials advise the user to curl and pipe some script of the net to install and make it work.
Why aren't we teaching people to be a little cautious - to download, review and then install?
How did developers become so lazy, and so coddled that we desire convenience over security or forethought?
Or worse, is it really due to an increasing number of developers who are unable rather than unwilling to review scripts, tools or libraries before use.
Do we need a new movement for 'the literate programmer', that emphasises the need to learn than just the core language or framework or ecosystem that they are using?
- MindTwister 14y agoScenario: I want to install rvm I could download their install script, read it through and then proceed to run it or, Since I'm trusting rvm not to do any harm in the first place, I might as well use their handy one-liner and install it in one go. Anything they can do in their one-liner they can do to me when I install rvm anyways.
- anon1385 14y agohttps://en.wikipedia.org/wiki/Underhanded_C_Contest https://en.wikipedia.org/wiki/Underhanded_C_Contest The Underhanded C Contest was a programming contest to turn out code that is malicious, but passes a rigorous inspection, and looks like an honest mistake. The contest rules define a task, and a malicious component. Entries must perform the task in a malicious manner as defined by the contest, and hide the malice.
- pnathan 14y agoIn general I don't want to spend time reading source of software I use. If I'm downloading a script from a trusted source, I like to be confident that I'm getting the right script. That's accomplished by the author publishing a sha256 hash and me following this workflow: curl http://scriptname > scriptname.foo sha256 scriptname # visually verify that it looks right from the web site chmod 755 ./scriptname.foo Of course, if I'm downloading from an untrusted source, I review the script and any commands I miss. Note that, e.g., Calibre, has their Linux update procedure to be as follows[1]: sudo python -c "import sys; py3 = sys.version_info[0] > 2; u = __import__('urllib.request' if py3 else 'urllib', fromlist=1); exec(u.urlopen('http://status.calibre-ebook.com/linux_installer').read()); main()" I'm sorry, but I don't see any verifications that calibre has not been rooted and malware installed. It's not HTTPS either, so I won't even get an SSL warning for a MITM attack. To decode the Python: that command/script downloads a script from the internet without verification, and executes it as root. [1] http://calibre-ebook.com/download_linux http://calibre-ebook.com/download_linux