Stroom – a scalable data storage, processing and analysis platform
github.com
github.com
bash <(curl -s https://gchq.github.io/stroom-resources/get_stroom.sh)
GCHQ (straight-faced): Just download and run this shell script we wrote. No funny business, we promise.NSA: snickers
I think there's space for a person, a company or a tool to certify all the scripts we run by passing the results of a curl directly into a shell. Wonder if there's any money in it.
Not sure what the need for the snide comment is.
Running them directly post-curl without even verifying a sum of some sort leaves me uncomfortable.
Besides it's a fun exercise to consider how you'd solve the problem of securing an installation script which are much more homogeneous in behavior than generic applications.
GitHub. The same place as the software. If you don't trust github.com's servers then you don't trust either the software or the installation script.
And when you find it, you still have to perform independent verification that the file on GitHub is the same one you are downloading through curl.
You are treating their installation instructions as equivalent to "clone this repo and run this script inside the repo" when they actually are not.
It's just whatever the github.com servers choose to serve you. Isn't that the point? If you trust what they serve you then it's safe to run, and if you don't then it isn't. Which is exactly the same situation as the software itself in the main repo isn't it?
How is curling and running a script any different to cloning it and running it?
Are you thinking that the fact that the repo has a commit hash saves you? What are you verifying the commit hash against? What you see on the website? The website also served by github.com? And how do you know the commit hash isn't accurate it's just a hash of code that does indeed contain attacking code?
I'm not sure any of it makes any difference. github.com can serve you code containing attacks from either the repo or the installation script and in both vectors you're just as vulnerable.