When everyone in the world INCLUDING cyber-security professionals seems to think that it's perfectly OK to download setup.exe or install.msi from sketchy driver mfgs. and run them. But SHARs and curl | sh is too scary!
It's not that any of these are a good idea, it's the blind-spot to traditional binary installers that's annoying. How do you audit them? Why are they OK (because they have to be)
rm -rf /path/to/directory
becomes rm -rf /path
if the connection accidentally drops half way. Or something less dramatic, but still leaving you in a broken state.Some people took the “don’t curl | sh” advice as “you have to inspect every line of a shell script installer you download”, which is of course absurd.
It'd only work if, like your example, it was the truncation that caused the flub. You can't have random corruption.
Does curl in a pipeline really behave that way - if the connection is interrupted (TCP RESET), does it just end the pipe? It probably actually does, from what I see.
It's an interesting edge case.
Personally I use, which would seem more immune:
curl -o /tmp/a
vi /tmp/a
{get bored easily, fuckit}
sh /tmp/a> Some people took the “don’t curl | sh” advice as “you have to inspect every line of a shell script installer you download”, which is of course absurd.
... to ever mean anything BUT "inspect every line". Which is, as you say, completely absurd.