In the end you need to basically blindly trust people if you're going to use their software (and the software needs root privileges)
The only problem i have with this is that you can get MITM'd. curl doesn't validate SSL certificates
In the end you need to basically blindly trust people if you're going to use their software (and the software needs root privileges)
The only problem i have with this is that you can get MITM'd. curl doesn't validate SSL certificates
I don't know Sealion and they can be amazing and all, so don't get this comment wrong.
If they want to support Linux systems properly, instead of using a script like that, I would recommend them to use packages and add support per distribution. Each distribution has different tools to add and manage services, and there are different ways to boot the system services. It's not just adding symlinks anymore because upstart and systemd, etc.
Also I'd love to cleanly upgrade/uninstall/etc their agent, so add a repo and I'll install your agent with more confidence.
How do I know I don't like how they install their agent? Because I didn't pipe the script directly into bash.
Curl has an option to explicitly disable cert validation:
-k, --insecure (SSL) This option explicitly allows curl to perform "insecure" SSL connections and transfers. All SSL connections are attempted to be made secure by using the CA certificate bundle installed by default. This makes all connections considered "insecure" fail unless -k, --insecure is used.
Maybe you're thinking of an older version?
(edited for formatting)
As for the product, it looks really good to me. No mention of encryption of stored data in the privacy statement, which might be a concern for some.
Also it wouldn't hurt to make checksums available for the installer and downloaded tar, for more paranoid folks like me.
This isn't so much different from downloading a random executable and running it. Hell, it's worse than that (since the download doesn't get stored for future audits)! But who said executing random executables from the internet is good in the first place?
It isn't, really. Both are creepy.