7 ms·
While fixing spotlight is a good idea (especially if you're opening it a lot in public), please don't blindly execute code without reading it first. While this
by mtrpcic 12y ago
While fixing spotlight is a good idea (especially if you're opening it a lot in public), please don't blindly execute code without reading it first. While this code isn't malicious, running misc. third party code without reading it first is a bad idea for everyone.
- morganvachon 12y agoThe fact that the entire source code is displayed on the page for all to read seems to have escaped you. You make a valid point in general, but the site in question practically screams the same message. I don't get why you have a problem with this particular project.
- equoid 12y agoThe fact that most people could look at that code and have no real clue what it actually does seems to have escaped you. This is in any event not the entire source code, as most of the work is done by function calls which most people would not know how to validate.
- morganvachon 12y agoIf the potential user doesn't understand what the script does, they have no business running it in the first place, so it's a moot point.
- jarcoal 12y agoI think he means you should at least read the code on the other end of that URL to make sure it matches what's on the site.
- pilsetnieks 12y agoPlus you should read what's downloaded to your machine before executing it, since there's also no guarantee that what's been served to your browser will be served to your curl.
- morganvachon 12y agoThat's just it: It does. Line for line, character for character (even space for space, which is important in Python). I wouldn't say what I did above without having diffed the file against the code displayed first. I just don't get the mentality here sometimes; someone creates a helpful script, puts the source code on their site for you to read and study, and the first instinct is to assume they have malicious intent before even taking a few minutes to read over it first. Hell, I'm no programmer but I know enough about the basics to follow exactly what the code does. It took me all of five minutes to decide that it flips two switches and nothing more. That the programming gods here can't or won't do that is telling. I get being paranoid about random scripts, but this one is on display for all to see before running. There is literally nothing hidden, yet you all act as if the author is trying to secretly take over your machines. It would be funny if it wasn't so pathetic.
- reedloden 12y agoPlease read http://www.djm.org.uk/protect-yourself-from-non-obvious-dangers-curl-url-pipe-sh/ http://www.djm.org.uk/protect-yourself-from-non-obvious-dang... (https://news.ycombinator.com/item?id=8385213 https://news.ycombinator.com/item?id=8385213).
- jboy55 12y agoActually what is displayed is not necessarily the same as what would be executed if you ran that script. You are viewing one piece of code , you will be executing a different file. In fact, you can view the github code, and see the code displayed is embedded into index.html (with syntax highlighting). If anyone is at all concerned with their privacy, they should never blindly run a script like that.
- morganvachon 12y agoCopy the text displayed in the code block on the page, diff it against the fix-macos.py file in the curl link. It is character for character the same code. Why am I the only one not too lazy to do this?
- jboy55 12y agoToday it is, tomorrow? A month from now? When the original dev ignores the site, and someone hacks his pw, changes the code, what then? I cannot seriously listen to anyone who "cares" about privacy, then asks their users to download and execute unknown code.
- morganvachon 12y agoIs the link in the curl line binary, compiled, non-human-readable code? No? Then your argument has no merit. It's a plaintext python script. Download it, parse it, if it checks out, run it. If it doesn't check out or you don't understand it, don't. It doesn't matter if it's today, a month from now, or a year from now. If the code checks out, and you feel like it will help you, run it. Or don't, and no one will care. Or are you seriously going to tell me that you feel you can't trust a 75 line script you just fully vetted, but you can trust, say, the Linux kernel, despite the fact that you didn't manually parse the millions of lines of code in it? If that really is your argument, then I can only imagine that you stop on green and go on red out in the real world, because that's pretty damn fucked up.
- jboy55 12y ago
- deleted 12y ago[deleted]
- itg 12y agoEspecially when you can do the same thing by going into system preferences. What a click bait title that leads people to run a script.
- brudgers 12y agoRunning miscellaneous second party code is also becoming increasingly problematic from a privacy standpoint...e.g. Windows 8 and Android [with Google services installed] also want to phone home.
- geographomics 12y agoThere's always the danger of this attack, as well: http://thejh.net/misc/website-terminal-copy-paste http://thejh.net/misc/website-terminal-copy-paste
- hk__2 12y agoHere it’s even worse because you don’t see the content of the script you’re executing.
- jonknee 12y agoWhat do you mean? The content is the majority of the web page... You can copy it from there, or if you're paranoid you can run: curl https://fix-macosx.com/fix-macosx.py Before the suggested: curl -o https://fix-macosx.com/fix-macosx.py && /usr/bin/python fix-macosx.py That said, at this stage just set the correct preferences. I had already done that before seeing this script, it's pretty simple.
- dmix 12y ago...This should just be the instructions: 1) $ curl -o https://fix-macosx.com/fix-macosx.py 1a) Review fix-macosx.py 2) $ /usr/bin/python fix-macosx.py
- moloch 12y agoIt's the same security model as downloading a binary and running it.
- arrrg 12y agoIt’s not “fixing” anything. It’s changing a preference people can have different opinions about.