Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
curl
35 Indlæg 26 Posters 113 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • heiglandreas@phpc.socialH heiglandreas@phpc.social

    @larsmb 🤣 I was shortly thinking that that is a chicken/egg situation if you want to install cURL via the `--install` option... 🙈

    pianosaurus@c.imP This user is from outside of this forum
    pianosaurus@c.imP This user is from outside of this forum
    pianosaurus@c.im
    wrote sidst redigeret af
    #20

    @larsmb @heiglandreas Let's just do a Microsoft, and ship every OS with something that isn't curl aliased as curl.

    1 Reply Last reply
    0
    • larsmb@mastodon.onlineL larsmb@mastodon.online

      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

      Finally a truly universal installer.

      fargate@tech.lgbtF This user is from outside of this forum
      fargate@tech.lgbtF This user is from outside of this forum
      fargate@tech.lgbt
      wrote sidst redigeret af
      #21

      @larsmb This is a plan without a flaw nor any possibility of error!

      1 Reply Last reply
      0
      • pianosaurus@c.imP pianosaurus@c.im

        @larsmb @agowa338 Lets have curl add a "Variant: without_vulnerabilities" header when --install is specified.

        mrshark@mathstodon.xyzM This user is from outside of this forum
        mrshark@mathstodon.xyzM This user is from outside of this forum
        mrshark@mathstodon.xyz
        wrote sidst redigeret af
        #22

        @pianosaurus @larsmb @agowa338

        I think RFC 3514 "The Security Flag in the IPv4 Header" have place here.

        https://www.rfc-editor.org/rfc/rfc3514

        1 Reply Last reply
        0
        • tux0r@layer8.spaceT tux0r@layer8.space

          @larsmb Also, curl should require sudo!

          busterb@infosec.exchangeB This user is from outside of this forum
          busterb@infosec.exchangeB This user is from outside of this forum
          busterb@infosec.exchange
          wrote sidst redigeret af
          #23

          @larsmb @tux0r you don't have curl setuid root already?

          1 Reply Last reply
          0
          • larsmb@mastodon.onlineL larsmb@mastodon.online

            Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

            Finally a truly universal installer.

            cos@sauna.socialC This user is from outside of this forum
            cos@sauna.socialC This user is from outside of this forum
            cos@sauna.social
            wrote sidst redigeret af
            #24

            @larsmb it should default to sudo to make things easy.

            1 Reply Last reply
            0
            • larsmb@mastodon.onlineL larsmb@mastodon.online

              Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

              Finally a truly universal installer.

              andrew@this.wplr.rocksA This user is from outside of this forum
              andrew@this.wplr.rocksA This user is from outside of this forum
              andrew@this.wplr.rocks
              wrote sidst redigeret af
              #25

              @larsmb please make it check a malware filter before passing it to $shell

              1 Reply Last reply
              0
              • larsmb@mastodon.onlineL larsmb@mastodon.online

                Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                Finally a truly universal installer.

                tbortels@infosec.exchangeT This user is from outside of this forum
                tbortels@infosec.exchangeT This user is from outside of this forum
                tbortels@infosec.exchange
                wrote sidst redigeret af
                #26

                @larsmb

                Not sure how "| sh" is any less secure than what people do 99.9% of the time anyway, which is download an installer or executable and not bother or validate it.

                If you really want to change the world, work out an actually secure mechanism (tall order!) and have --install implement it. Not sure what that would look like: https requirement, maybe a database of known/vetted installations, a means to report issues. Very tall order.

                christopherkunz@chaos.socialC 1 Reply Last reply
                0
                • tbortels@infosec.exchangeT tbortels@infosec.exchange

                  @larsmb

                  Not sure how "| sh" is any less secure than what people do 99.9% of the time anyway, which is download an installer or executable and not bother or validate it.

                  If you really want to change the world, work out an actually secure mechanism (tall order!) and have --install implement it. Not sure what that would look like: https requirement, maybe a database of known/vetted installations, a means to report issues. Very tall order.

                  christopherkunz@chaos.socialC This user is from outside of this forum
                  christopherkunz@chaos.socialC This user is from outside of this forum
                  christopherkunz@chaos.social
                  wrote sidst redigeret af
                  #27

                  @tbortels Well that's, like... a package manager? Let's call it cURL Universal Package System and abbreviate it CUPS... oh damn.

                  tbortels@infosec.exchangeT larsmb@mastodon.onlineL 2 Replies Last reply
                  0
                  • christopherkunz@chaos.socialC christopherkunz@chaos.social

                    @tbortels Well that's, like... a package manager? Let's call it cURL Universal Package System and abbreviate it CUPS... oh damn.

                    tbortels@infosec.exchangeT This user is from outside of this forum
                    tbortels@infosec.exchangeT This user is from outside of this forum
                    tbortels@infosec.exchange
                    wrote sidst redigeret af
                    #28

                    @christopherkunz

                    Sadly I think I trust Badger and friends to get it right more than my package manager.

                    CUPS. Now that's a name I've not heard in a long time...

                    1 Reply Last reply
                    0
                    • larsmb@mastodon.onlineL larsmb@mastodon.online

                      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                      Finally a truly universal installer.

                      brouhaha@mastodon.socialB This user is from outside of this forum
                      brouhaha@mastodon.socialB This user is from outside of this forum
                      brouhaha@mastodon.social
                      wrote sidst redigeret af
                      #29

                      @larsmb
                      "| sh" _IS_ the curl install option

                      1 Reply Last reply
                      0
                      • larsmb@mastodon.onlineL larsmb@mastodon.online

                        Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                        Finally a truly universal installer.

                        freddy@social.security.plumbingF This user is from outside of this forum
                        freddy@social.security.plumbingF This user is from outside of this forum
                        freddy@social.security.plumbing
                        wrote sidst redigeret af
                        #30

                        @larsmb pair it with some yet-to-be-specified `integrity` parameter to check the file and we're there.

                        1 Reply Last reply
                        0
                        • tux0r@layer8.spaceT tux0r@layer8.space

                          @larsmb Also, curl should require sudo!

                          N This user is from outside of this forum
                          N This user is from outside of this forum
                          nilclass@infosec.exchange
                          wrote sidst redigeret af
                          #31

                          @tux0r @larsmb when curl is invoked with `sudo`, sites should be prohibited from refusing access

                          1 Reply Last reply
                          0
                          • larsmb@mastodon.onlineL larsmb@mastodon.online

                            Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                            Finally a truly universal installer.

                            nyansen@elbmatsch.deN This user is from outside of this forum
                            nyansen@elbmatsch.deN This user is from outside of this forum
                            nyansen@elbmatsch.de
                            wrote sidst redigeret af
                            #32

                            @larsmb maybe --execute will be a better option because its not always a Installation script.

                            larsmb@mastodon.onlineL 1 Reply Last reply
                            0
                            • christopherkunz@chaos.socialC christopherkunz@chaos.social

                              @tbortels Well that's, like... a package manager? Let's call it cURL Universal Package System and abbreviate it CUPS... oh damn.

                              larsmb@mastodon.onlineL This user is from outside of this forum
                              larsmb@mastodon.onlineL This user is from outside of this forum
                              larsmb@mastodon.online
                              wrote sidst redigeret af
                              #33

                              @christopherkunz @tbortels Package managers are so awesome we have hundreds.

                              1 Reply Last reply
                              0
                              • nyansen@elbmatsch.deN nyansen@elbmatsch.de

                                @larsmb maybe --execute will be a better option because its not always a Installation script.

                                larsmb@mastodon.onlineL This user is from outside of this forum
                                larsmb@mastodon.onlineL This user is from outside of this forum
                                larsmb@mastodon.online
                                wrote sidst redigeret af
                                #34

                                @nyansen Ohhh how about "--rootkit"

                                nyansen@elbmatsch.deN 1 Reply Last reply
                                0
                                • larsmb@mastodon.onlineL larsmb@mastodon.online

                                  @nyansen Ohhh how about "--rootkit"

                                  nyansen@elbmatsch.deN This user is from outside of this forum
                                  nyansen@elbmatsch.deN This user is from outside of this forum
                                  nyansen@elbmatsch.de
                                  wrote sidst redigeret af
                                  #35

                                  @larsmb for a curl anti cheat system?

                                  1 Reply Last reply
                                  0
                                  • strit@mastodon.socialS strit@mastodon.social shared this topic
                                  Svar
                                  • Svar som emne
                                  Login for at svare
                                  • Ældste til nyeste
                                  • Nyeste til ældste
                                  • Most Votes


                                  • Log ind

                                  • Har du ikke en konto? Tilmeld

                                  • Login or register to search.
                                  Powered by NodeBB Contributors
                                  Graciously hosted by data.coop
                                  • First post
                                    Last post
                                  0
                                  • Hjem
                                  • Seneste
                                  • Etiketter
                                  • Populære
                                  • Verden
                                  • Bruger
                                  • Grupper