you are viewing a single comment's thread
view the rest of the comments
[–] 15 points 4 months ago* (4 children)

Which is a fairly high hurdle for an attacker in most instances.

With software projects training people that curl <link to their install script> | bash is totally fine and the insane amount of supply chain attacks lately it's a critical bug that's just begging to be exploited on single user systems.

So yes, patch your systems and definitely do not downplay this.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 6 points 4 months ago (3 children)

    With software projects training people that curl | bash is totally fine and the insane amount of supply chain attacks lately it’s a critical bug that’s just begging to be exploited on single user systems.

    I wish the worst case of gout on people who do this. I can't believe it's become such an accepted way of installing software.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 8 points 4 months ago (1 child)

    I have a vague memory of some project that did this ages ago where you could see the script on their web page but when you ran the command it executed a different script (there was a single-character difference in the URL) and the result was it told you not to be so dumb as to run scripts like that.

  • source
  • parent
  • hideshow 1 child comment