Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
curl
35 Indlæg 26 Posters 113 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • vyskocilm@witter.czV vyskocilm@witter.cz

    @larsmb
    --insecure is implicit in this mode, correct?

    larsmb@mastodon.onlineL This user is from outside of this forum
    larsmb@mastodon.onlineL This user is from outside of this forum
    larsmb@mastodon.online
    wrote sidst redigeret af
    #7

    @vyskocilm Snark aside, with "https" probably as (in)secure as getting the respective package from any community distribution.

    1 Reply Last reply
    0
    • larsmb@mastodon.onlineL larsmb@mastodon.online

      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

      Finally a truly universal installer.

      agowa338@chaos.socialA This user is from outside of this forum
      agowa338@chaos.socialA This user is from outside of this forum
      agowa338@chaos.social
      wrote sidst redigeret af
      #8

      @larsmb But does it also leak to the server that you're using "--install" and not just try to download the file so that when you're trying to just download the malicious script the server can send you a version without the malware instead?

      pianosaurus@c.imP 1 Reply Last reply
      0
      • larsmb@mastodon.onlineL larsmb@mastodon.online

        Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

        Finally a truly universal installer.

        totenlegionchris@metalhead.clubT This user is from outside of this forum
        totenlegionchris@metalhead.clubT This user is from outside of this forum
        totenlegionchris@metalhead.club
        wrote sidst redigeret af
        #9

        @larsmb This should work fine with openclaw!! You are ahead of the time.

        1 Reply Last reply
        0
        • henryk@chaos.socialH henryk@chaos.social

          @larsmb You could then extend https://xkcd.com/1654/ with `curl --install "https://get${1}.dev/install.sh" &`

          benedikt_lauenburg@norden.socialB This user is from outside of this forum
          benedikt_lauenburg@norden.socialB This user is from outside of this forum
          benedikt_lauenburg@norden.social
          wrote sidst redigeret af
          #10

          @henryk @larsmb misses an ai api call.

          1 Reply Last reply
          0
          • larsmb@mastodon.onlineL larsmb@mastodon.online

            Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

            Finally a truly universal installer.

            heiglandreas@phpc.socialH This user is from outside of this forum
            heiglandreas@phpc.socialH This user is from outside of this forum
            heiglandreas@phpc.social
            wrote sidst redigeret af
            #11

            @larsmb 🤣 I was shortly thinking that that is a chicken/egg situation if you want to install cURL via the `--install` option... 🙈

            pianosaurus@c.imP 1 Reply Last reply
            0
            • larsmb@mastodon.onlineL larsmb@mastodon.online

              Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

              Finally a truly universal installer.

              moritzboth@chaos.socialM This user is from outside of this forum
              moritzboth@chaos.socialM This user is from outside of this forum
              moritzboth@chaos.social
              wrote sidst redigeret af
              #12

              @larsmb better naming: "--submit" or "--infect"

              1 Reply Last reply
              0
              • larsmb@mastodon.onlineL larsmb@mastodon.online

                Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                Finally a truly universal installer.

                l29ah@qoto.orgL This user is from outside of this forum
                l29ah@qoto.orgL This user is from outside of this forum
                l29ah@qoto.org
                wrote sidst redigeret af
                #13

                @larsmb This is much longer to type than |sh -

                1 Reply Last reply
                0
                • larsmb@mastodon.onlineL larsmb@mastodon.online

                  Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                  Finally a truly universal installer.

                  aspragg@ohai.socialA This user is from outside of this forum
                  aspragg@ohai.socialA This user is from outside of this forum
                  aspragg@ohai.social
                  wrote sidst redigeret af
                  #14

                  @larsmb Bonus, it would stop people getting confused from typing `sudo curl $URL | sh -` instead of `curl $URL | sudo sh -`

                  ...nope, still nope! 😆

                  1 Reply Last reply
                  0
                  • larsmb@mastodon.onlineL larsmb@mastodon.online

                    Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                    Finally a truly universal installer.

                    agateau@mastodon.xyzA This user is from outside of this forum
                    agateau@mastodon.xyzA This user is from outside of this forum
                    agateau@mastodon.xyz
                    wrote sidst redigeret af
                    #15

                    @larsmb What could possibly go wrong? 🙂

                    1 Reply Last reply
                    0
                    • tux0r@layer8.spaceT tux0r@layer8.space

                      @larsmb Also, curl should require sudo!

                      ozzelot@mstdn.socialO This user is from outside of this forum
                      ozzelot@mstdn.socialO This user is from outside of this forum
                      ozzelot@mstdn.social
                      wrote sidst redigeret af
                      #16

                      @tux0r
                      doas users made a sad face. all five of us.
                      @larsmb

                      tux0r@layer8.spaceT 1 Reply Last reply
                      0
                      • larsmb@mastodon.onlineL larsmb@mastodon.online

                        Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                        Finally a truly universal installer.

                        amenonsen@mastodon.socialA This user is from outside of this forum
                        amenonsen@mastodon.socialA This user is from outside of this forum
                        amenonsen@mastodon.social
                        wrote sidst redigeret af
                        #17

                        @larsmb Or `curl --bash`

                        1 Reply Last reply
                        0
                        • ozzelot@mstdn.socialO ozzelot@mstdn.social

                          @tux0r
                          doas users made a sad face. all five of us.
                          @larsmb

                          tux0r@layer8.spaceT This user is from outside of this forum
                          tux0r@layer8.spaceT This user is from outside of this forum
                          tux0r@layer8.space
                          wrote sidst redigeret af
                          #18

                          @ozzelot @larsmb (sad pfexec noises)

                          1 Reply Last reply
                          0
                          • agowa338@chaos.socialA agowa338@chaos.social

                            @larsmb But does it also leak to the server that you're using "--install" and not just try to download the file so that when you're trying to just download the malicious script the server can send you a version without the malware instead?

                            pianosaurus@c.imP This user is from outside of this forum
                            pianosaurus@c.imP This user is from outside of this forum
                            pianosaurus@c.im
                            wrote sidst redigeret af
                            #19

                            @larsmb @agowa338 Lets have curl add a "Variant: without_vulnerabilities" header when --install is specified.

                            mrshark@mathstodon.xyzM 1 Reply Last reply
                            0
                            • heiglandreas@phpc.socialH heiglandreas@phpc.social

                              @larsmb 🤣 I was shortly thinking that that is a chicken/egg situation if you want to install cURL via the `--install` option... 🙈

                              pianosaurus@c.imP This user is from outside of this forum
                              pianosaurus@c.imP This user is from outside of this forum
                              pianosaurus@c.im
                              wrote sidst redigeret af
                              #20

                              @larsmb @heiglandreas Let's just do a Microsoft, and ship every OS with something that isn't curl aliased as curl.

                              1 Reply Last reply
                              0
                              • larsmb@mastodon.onlineL larsmb@mastodon.online

                                Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                                Finally a truly universal installer.

                                fargate@tech.lgbtF This user is from outside of this forum
                                fargate@tech.lgbtF This user is from outside of this forum
                                fargate@tech.lgbt
                                wrote sidst redigeret af
                                #21

                                @larsmb This is a plan without a flaw nor any possibility of error!

                                1 Reply Last reply
                                0
                                • pianosaurus@c.imP pianosaurus@c.im

                                  @larsmb @agowa338 Lets have curl add a "Variant: without_vulnerabilities" header when --install is specified.

                                  mrshark@mathstodon.xyzM This user is from outside of this forum
                                  mrshark@mathstodon.xyzM This user is from outside of this forum
                                  mrshark@mathstodon.xyz
                                  wrote sidst redigeret af
                                  #22

                                  @pianosaurus @larsmb @agowa338

                                  I think RFC 3514 "The Security Flag in the IPv4 Header" have place here.

                                  https://www.rfc-editor.org/rfc/rfc3514

                                  1 Reply Last reply
                                  0
                                  • tux0r@layer8.spaceT tux0r@layer8.space

                                    @larsmb Also, curl should require sudo!

                                    busterb@infosec.exchangeB This user is from outside of this forum
                                    busterb@infosec.exchangeB This user is from outside of this forum
                                    busterb@infosec.exchange
                                    wrote sidst redigeret af
                                    #23

                                    @larsmb @tux0r you don't have curl setuid root already?

                                    1 Reply Last reply
                                    0
                                    • larsmb@mastodon.onlineL larsmb@mastodon.online

                                      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                                      Finally a truly universal installer.

                                      cos@sauna.socialC This user is from outside of this forum
                                      cos@sauna.socialC This user is from outside of this forum
                                      cos@sauna.social
                                      wrote sidst redigeret af
                                      #24

                                      @larsmb it should default to sudo to make things easy.

                                      1 Reply Last reply
                                      0
                                      • larsmb@mastodon.onlineL larsmb@mastodon.online

                                        Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                                        Finally a truly universal installer.

                                        andrew@this.wplr.rocksA This user is from outside of this forum
                                        andrew@this.wplr.rocksA This user is from outside of this forum
                                        andrew@this.wplr.rocks
                                        wrote sidst redigeret af
                                        #25

                                        @larsmb please make it check a malware filter before passing it to $shell

                                        1 Reply Last reply
                                        0
                                        • larsmb@mastodon.onlineL larsmb@mastodon.online

                                          Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                                          Finally a truly universal installer.

                                          tbortels@infosec.exchangeT This user is from outside of this forum
                                          tbortels@infosec.exchangeT This user is from outside of this forum
                                          tbortels@infosec.exchange
                                          wrote sidst redigeret af
                                          #26

                                          @larsmb

                                          Not sure how "| sh" is any less secure than what people do 99.9% of the time anyway, which is download an installer or executable and not bother or validate it.

                                          If you really want to change the world, work out an actually secure mechanism (tall order!) and have --install implement it. Not sure what that would look like: https requirement, maybe a database of known/vetted installations, a means to report issues. Very tall order.

                                          christopherkunz@chaos.socialC 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper