In what world is that secure?
Pity Qubes is so heavy, otherwise I'd be using it
In what world is that secure?
Pity Qubes is so heavy, otherwise I'd be using it
install:
[ $(id -u) -ne 0 ] && echo 'please run sudo make install' || curl https//my.thing | /bin/sh
it goes back to what jve said - it's a matter of trust. how often do you blindly run 'sudo make install' w/o reading the entirety of the build script? all the time I bet - it's because you trust the sourceI think I have never run `sudo make install`. Things I install come from package managers. Docker or a VM is used to test other software.
And of course trust is important, but if I encounter things like `curl | bash`, my trust is lost.
But curl https://example.com/installer.sh | bash is not? Why?
https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
If I have a makefile, I can inspect it and see what it does.
If I have shell script (or indeed a makefile!) that calls `curl | bash`, I can inspect that shell script and see the URL that is used with curl, and then inspect the contents that the URL returns.
TBH, while I take your point, I do think it's a little disingenuous of you to claim that "You don't have the opportunity" to inspect the script prior to executing it - you ordinarily will, but can't in the unlikely event of an attack like the article describes, which would require an attacker to be in full control of the web server.
Off the top of my head, this could be mitigated in a couple of ways:
1. Hash a known-good script and check the hash matches prior to executing (this does however mean that you need to update the hash every time the remote script is changed)
2. Use curl to download the remote script to a local file first, and provide the opportunity to inspect it prior to piping it into bash
Or the third opportunity of not piping curl to bash and using a proper repository that has all these integrity and authenticity checks built-in.
The problem is that cattle should apply only to containers, not hosts or VMs. Why? root. Which is also why Docker is a nonstarter for anyone who wants to use containers securely.