| ▲ | 1over137 2 hours ago |
| “You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read. |
|
| ▲ | jtrueb 2 hours ago | parent | next [-] |
| Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run. |
| |
| ▲ | jacquesm 2 hours ago | parent [-] | | Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example. | | |
| ▲ | nvme0n1p1 2 hours ago | parent | next [-] | | The script, and the code the script downloads, both come from the same repo and were written by the same developer. If you've already decided you trust the author, what's the actual threat here? | | |
| ▲ | jacquesm 2 hours ago | parent [-] | | I would not trust the author just like that. But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better. | | |
| ▲ | user43928 2 hours ago | parent [-] | | I think the point is that when a repo contains: program.bin
install.sh
It seems rather pointless for me to thoroughly inspect the install script before I run the program. |
|
| |
| ▲ | halJordan 2 hours ago | parent | prev [-] | | You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are | | |
| ▲ | kbolino an hour ago | parent [-] | | App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft). | | |
|
|
|
|
| ▲ | tmpz22 2 hours ago | parent | prev [-] |
| Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment. Its a different threat model. You should not curl bash. |
| |
| ▲ | benterix 2 hours ago | parent [-] | | Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get. But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them. |
|