151 points privacyisntdead 1 hour ago 70 comments
arialdomartini 1 hour ago | parent
demibabs 1 hour ago | parent
1over137 1 hour ago | parent
jtrueb 1 hour ago | parent
jacquesm 47 minutes ago | parent
nvme0n1p1 26 minutes ago | parent
If you've already decided you trust the author, what's the actual threat here?
jacquesm 23 minutes ago | parent
But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.
user43928 17 minutes ago | parent
program.bin
install.sh
It seems rather pointless for me to thoroughly inspect the install script before I run the program.halJordan 21 minutes ago | parent
kbolino 10 minutes ago | parent
tmpz22 1 hour ago | parent
Its a different threat model. You should not curl bash.
benterix 35 minutes ago | parent
But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them.
aaomidi 1 hour ago | parent
Like I get why it’s bad, but also homebrew package installation is a more organized version of this.
Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…
packeted 1 hour ago | parent
hypeatei 1 hour ago | parent
They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.
mogwire 1 hour ago | parent
Excuse me, they are TLS certs.
Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs
maccard 58 minutes ago | parent
mingus88 49 minutes ago | parent
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
zakki 39 minutes ago | parent
stock_toaster 33 minutes ago | parent
porridgeraisin 48 minutes ago | parent
curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
> The server knows you’re piping — and can lie
This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.
> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.
Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]
> You can’t reproduce what ran
`| tee inspect.sh | bash`
> Add sudo and it’s game over
Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.
[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.
hnfong 31 minutes ago | parent
Please take a look at this before making any assertions... https://github.com/omlahore/RemoveMacAI/blob/main/install.sh
Terr_ 30 minutes ago | parent
The problem is that:
1. The effort and care needed to test is unnecessarily high. You've got to guard against way more tricks from an interactive source that can see you and choose what it's going to deliver and how.
2. With no "standard" artifact that can be exactly compared, that work cannot be shared.
In contrast, release_1.2.3.zip isn't going to mutate under you and everybody can agree on what its size/hash/bytes ought to be, and if it deviates from that it sets off alarm-bells.
> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
Why would a convention often followed by good/careful actors bind what malicious/careless people create?
bigyabai 1 hour ago | parent
nomel 1 hour ago | parent
behnamoh 1 hour ago | parent
nvme0n1p1 21 minutes ago | parent
What's that? You didn't pay Apple's 1200% markup on storage, just so you can have enough room for your actual work after the OS fills your disk with a bunch of bloat? What are you, poor?
trollbridge 57 minutes ago | parent
swozey 1 hour ago | parent
trollbridge 57 minutes ago | parent
drnick1 55 minutes ago | parent
GNOME has reached maturity and hasn't changed significantly in years, while Apple is busy destroying macOS.
dijit 43 minutes ago | parent
I should applaud their efforts, and I get that much of it is voluntary, but their bugs are numerous, notable and the way they interact with the rest of the universe (both people with accessibility needs, and the wider developer ecosystem on linux) can most accurately be described as arrogant and hostile.
KDE is the bastion of maturity here, and I would agree that it is mature.
I’m not sure how the love for GNOME continues when KDE (while not my personal choice) has clearly been running circles around it since GNOME3 and the gap has only widened since that change too.
bigyabai 24 minutes ago | parent
Angostura 14 minutes ago | parent
Personally, my limited experimentation with Apple AI has left me quite liking it.
The contents of the Exportable’Privacy Report’ are interesting to look through
behnamoh 1 hour ago | parent
doawoo 1 hour ago | parent
wartywhoa23 1 hour ago | parent
NamlchakKhandro 1 hour ago | parent
pjmlp 55 minutes ago | parent
ultrarunner 49 minutes ago | parent
fmajid 47 minutes ago | parent
Apple is an advertising company and thus inherently untrustworthy.
hypfer 59 minutes ago | parent
What's going on at Apple product strategy?
userbinator 44 minutes ago | parent
Could the rise of LLMs and vibe-coding have motivated people who otherwise wouldn't bother?
gumby 34 minutes ago | parent
neya 8 minutes ago | parent
I'm not sure there were enough people looking at finder and thinking "I wish I could talk to an AI to open a file on my desktop which I could've simply double clicked on anyway"
jojobas 7 minutes ago | parent
the_arun 37 minutes ago | parent
pyaamb 36 minutes ago | parent
nailer 27 minutes ago | parent
Huh cool. They're doing curl | bash properly.
woodruffw 14 minutes ago | parent
(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)
neuroelectron 27 minutes ago | parent
I switched to MacOS 3 years ago because of Microsoft and the writing on the wall seems to say I got another year left before I'm forced into Linux. Because if I have to maintain my own OS then I might as well install Linux and do it once.
pietz 25 minutes ago | parent
formvoltron 15 minutes ago | parent
Does apple not realize there is an SSD crisis happening? Used to love apple (Apple IIc was my first computer). But now? Terrible.
ryandrake 9 minutes ago | parent
azinman2 1 minute ago | parent