Netboot
netboot.xyz
netboot.xyz
Sarcasm aside, at the very least it would have been nice to see it use iPXE's `imgtrust` and `imgverify` functionality, which I could then audit and load on to a boot medium for netboot use.
To be honest, this looks like a cool project. I've always wanted a way to PXE without having to need another host on the LAN.
I'm not familiar with these but I saw a commit from just a couple of hours ago referencing "image trust" [1], so maybe it's in the works now following your comment?
[1]: https://github.com/antonym/netboot.xyz/commit/25910be18da219...
Also, if it is just to try out a new OS in a virtual machine, I guess it is okay to use such a service :).
The idea is really cool, specifically I'd use this for the raspberry pi. I hope someone does some major security maintenance on this
Running untrusted code is one thing, running it after pulling it from the internet is an ENTIRELY different subject.
People download third party docker contains. I can't see how this is worse.
sh | wget http://www...something.com/install.sh
to install something automatically! Way too many projects do it, from my head: rvm and oh-my-zsh.
In theory, yes, `curl | sh` is the same as configure&make is the same as downloading your initial iso image and installing the system from it. In practice they have different risks associated with them.
What about `cd /usr/ports/www/firefox && make clean install`?
For nefarious purposes I actually think it's worse than the much-maligned "curl|sh" scenario. I bet a reasonable number of people will end up trying to download the script, out of curiosity if nothing else. If it's doing anything not straightforward, it would get attention. In contrast, who would notice a line added to the middle of a 8000 line auto-generated configure script?
The point is, technically there isn't anything different between `curl | sh` and installing a system from either a downloaded .iso or a mailed DVD. Both run code from untrusted sources on your computer. But in practice they're very different because of user behaviour and ability to validate data before running. There's a whole spectrum in between and configure&make is somewhere on it.
Of course, you have to start trusting at some point. But with HTTP, you have to also trust the wifi AP, its owner, all of the routers between you and the server, DNS... At least https takes a lot of those (but not all) out of the equation, while GPG goes even further.
If you download the code manually, how are you to know that the server sent you the exact same code? They could be checking HTTP headers for a bootloader device, or might only be infecting 1 in 100 downloads. You'd never spot it.
Going signed CA wouldn't be hard to do in this case at all, it's just part of the build process actually but only gets you to to a trusted PXE+menu system. After getting into the PXE menu a system could still hijack the upstream kernel/initrd files.
Even freebsd netinstall (aka not limited to linux installers) is just http/ftp without any package signing. The whole ecosystem probably needs to mature some more in regards to verification that won't break downstream projects such as this.
Fyi, I first heard about Netboot via the cron.weekly newsletter last Sunday, it seems to be a very new project that's only just been released: http://www.cronweekly.com/issue-11/