curl -L https://git.io/cleansweep | sh
For a security tool?[edit] I still think it's a great idea, though [/edit]
curl -L https://git.io/cleansweep | sh
For a security tool?[edit] I still think it's a great idea, though [/edit]
[1] https://sandstorm.io/news/2015-09-24-is-curl-bash-insecure-p...
He addresses code signing and mitm and connection interruptions.
Edit: The gist of it is no, it's not more insecure than other software distribution methods.
https://github.com/PatchworkSecurity/cleansweep/blob/master/...
The comments explain what is happening at each step.
It looks like Patchwork's script doesn't quite do that, but it does put _most_ of its functionality into functions, and AFAICT there is no particular place in the script where a connection loss could lead to anything bad happening. Admittedly this appears to be a lucky accident rather than following best practice.
Thanks for the link. I've filed an issue and should have this fixed tonight
I don't particularly like curl | sh either, but without sudo, I'm not sure how much it /really/ differs, security wise, from other options.
Edit: real package managers have improved features compared to curl, as outlined in another branch of the comments.
https://patchworksecurity.com/releases.txt
The latest release (2.0.0) has been signed by my key 0x85C64E20
We're working on improving our API documentation. You can develop against our API and not use the supplied client.