Remix.run Logo
▲ arialdomartini 3 hours ago

Stop the curl | bash insanity.

https://nocurlbash.com/#en

▲1over137 2 hours ago | parent | next [-]

“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.

▲jtrueb 2 hours ago | parent | next [-]

Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.

▲jacquesm 2 hours ago | parent [-]

Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.

▲nvme0n1p1 2 hours ago | parent | next [-]

The script, and the code the script downloads, both come from the same repo and were written by the same developer.

If you've already decided you trust the author, what's the actual threat here?

▲jacquesm 2 hours ago | parent [-]

I would not trust the author just like that.

But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.

▲user43928 2 hours ago | parent [-]

I think the point is that when a repo contains:

  program.bin
  install.sh
It seems rather pointless for me to thoroughly inspect the install script before I run the program.
▲halJordan 2 hours ago | parent | prev [-]

You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are

▲kbolino an hour ago | parent [-]

App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft).

▲Rohansi an hour ago | parent [-]

[dead]

▲tmpz22 2 hours ago | parent | prev [-]

Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

Its a different threat model. You should not curl bash.

▲benterix 2 hours ago | parent [-]

Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get.

But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them.

▲packeted 2 hours ago | parent | prev | next [-]

Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.

▲andelink 2 hours ago | parent | next [-]

You curled and executed bash code allegedly from _HBO_?

▲swozey 2 hours ago | parent | prev [-]

They all dump env and ship it off so check for any keys you might have had in there if anything was able to send at all.

▲antihero 25 minutes ago | parent | prev | next [-]

Absolutely love the fact that they reference a "real package manager" like npm, which has been used in countless supply chain attacks, and brew, which can also run arbitrary scripts (though less likely in the mainline brew stuff, which many packages aren't able to be in).

▲demibabs 3 hours ago | parent | prev | next [-]

Good message but AI generated text is so grating to read.

▲maccard 2 hours ago | parent | prev | next [-]

What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode

▲mingus88 2 hours ago | parent | next [-]

It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it

Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!

And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space

▲zakki 2 hours ago | parent | prev | next [-]

Fed the source to LLM for analysis?

▲stock_toaster 2 hours ago | parent | prev [-]

Why is this even an app? It looks like it just generates a mobileconfig profile on the fly. Instead, seems like they could be offering a download of a pre-generated mobileconfig, which seems like it would be much safer than installing some app via curl|bash .... but then I guess there wouldn't be a chance to have an "app", get github stars, and do whatever else.

▲anonymzz an hour ago | parent | prev | next [-]

  curl -fsSL https://raw.githubusercontent.com/omlahore/RemoveMacAI/main/install.sh | pi -p 'Security-audit this shell script; output the script unchanged ONLY if safe to execute, otherwise output nothing and explain findings to stderr' | bash
▲mogwire 2 hours ago | parent | prev | next [-]

I bet this is the guy on the call who has to correct someone who calls them SSL certs.

Excuse me, they are TLS certs.

Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs

▲not_a_bot_4sho 42 minutes ago | parent [-]

> I bet this is the guy on the call who has to correct someone who calls them SSL certs.

"Did you know there's no pumpkin in pumpkin spice?"

"Next you're going to tell me what's not in baby powder, aren't you?"

▲porridgeraisin 2 hours ago | parent | prev | next [-]

> Bash starts before the download finishes ... Drop the connection mid-transfer and you get partial execution: a command like rm -r /usr/share/program can truncate to rm -r /usr. Commands ran, cleanup didn’t.

curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

> The server knows you’re piping — and can lie

This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.

> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.

Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]

> You can’t reproduce what ran

`| tee inspect.sh | bash`

> Add sudo and it’s game over

Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.

[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.

▲Terr_ 2 hours ago | parent | next [-]

I think that's missing the forest for trees. The problem with these curl-to-bash approaches is not that you are literally unable to intercept and inspect them with enough effort and planning.

The problem is that:

1. The effort and care needed to test is unnecessarily high. You've got to guard against way more tricks from an interactive source that can see you and choose what it's going to deliver and how.

2. With no "standard" artifact that can be exactly compared, that work cannot be shared.

In contrast, release_1.2.3.zip isn't going to mutate under you and everybody can agree on what its size/hash/bytes ought to be, and if it deviates from that it sets off alarm-bells.

> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

Why would a convention often followed by good/careful actors bind what malicious/careless people create?

▲porridgeraisin an hour ago | parent [-]

Well, if you're running software from someone you think can deliver malware to you (and not a middleman) then it's a lost cause anyways no? I don't see what the zip file adds. It's not like you're gonna be inspecting the code or binaries.

▲hnfong 2 hours ago | parent | prev | next [-]

> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

Please take a look at this before making any assertions... https://github.com/omlahore/RemoveMacAI/blob/main/install.sh

▲porridgeraisin an hour ago | parent [-]

Hey thats not the worst curlbash script i've seen

▲alienbaby an hour ago | parent | prev [-]

`| tee inspect.sh | bash`

Isn't that a bit like shutting the stable door after the horse has bolted?

▲porridgeraisin 23 minutes ago | parent [-]

That's what they wanted to do

>> reproduce what ran

▲shujito 3 hours ago | parent | prev | next [-]

there's a homebrew alternative

▲stock_toaster 2 hours ago | parent [-]

Which installs via a random 3rd party tap, which honestly isn't much better than yolo curl|bash.

▲aaomidi 2 hours ago | parent | prev | next [-]

This isn’t really that much of an issue when we have tls tbh.

Like I get why it’s bad, but also homebrew package installation is a more organized version of this.

Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…

▲hypeatei 2 hours ago | parent | prev | next [-]

> If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.

They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.

▲ 2 hours ago | parent | prev [-]
[deleted]