‹ BackHN Continuity

Thread

Fakecloud: Local AWS cloud emulator for integration tests

154 points · 78 comments · theanonymousone

  1. otterley · · focus · HN ↗
    There’s also MiniStack, which forked from LocalStack after they started breaking developer workflows: <a href="https:&#x2F;&#x2F;ministack.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ministack.org&#x2F;

    Both fakecloud and its website look sloppily vibe-coded, and its “authors” are anonymous. It’s going to take a while for it to earn trust. I’d treat it with suspicion. (Curl-to-shell pipe to install? Ugh.)

    1. straygarr · · focus · HN ↗
      Agreed with everything up to:

      &quot;curl-to-shell pipe to install&quot; - what&#x27;s the problem here? that&#x27;s pretty common on linux systems and something the AWS CLI uses.

      Or is the problem the fact that this dev is untrusted and is executing a possibly malicious script on your machine?

      1. MisterMunchkin · · focus · HN ↗
        Running arbitrary code directly in your terminal is very dangerous
        1. luma · · focus · HN ↗
          Any code I didn&#x27;t write is arbitrary code. At some point I&#x27;m left to trust someone or run no software at all.
          1. mulmen · · focus · HN ↗
            It’s a shell script. You can download and read it before you run it. Piping it directly to the shell is reckless.

            I’m not sure how your machine is configured but mine has permission boundaries and security policies that make sure programs are behaving properly. I don’t run everything with my personal user context.

            1. mynameisvlad · · focus · HN ↗
              So then... Just do that and it&#x27;s no longer reckless.

              If someone wants to be reckless they can be. If someone doesn&#x27;t, they also have that ability.

            2. bornfreddy · · focus · HN ↗
              Actually... Server can detect if you are piping or not and serve a modified version for inspection.

              But really, there is no reason not to use prebuilt packages for distribution. Curlpiping needs to die.

              1. [deleted] · · focus · HN ↗

                [deleted]

              2. otterley · · focus · HN ↗
                At first I thought “this sounds like bullshit” but then found <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230408195648&#x2F;https:&#x2F;&#x2F;www.idontplaydarts.com&#x2F;2016&#x2F;04&#x2F;detecting-curl-pipe-bash-server-side" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230408195648&#x2F;https:&#x2F;&#x2F;www.idont...
              3. [deleted] · · focus · HN ↗

                [deleted]

              4. mulmen · · focus · HN ↗
                Package distribution is the best solution but why would you download the install script a second time?
        2. john01dav · · focus · HN ↗
          If you&#x27;re about to install an upstream binary with this and you&#x27;re not reviewing this then it&#x27;s purely (irrational) vibes to be concerned with the also unreviewed shell script from the same source.
          1. NewJazz · · focus · HN ↗
            Yeah but at least with a binary you can verify the checksum of a recent official immutable github release rathrr than just trust a script hosted on the website.
            1. darkwater · · focus · HN ↗
              If you don&#x27;t really trust the author, what&#x27;s a checksum going to provide you? That the maybe malicious code released on GH has not been tampered with? Not so helpful.
              1. NewJazz · · focus · HN ↗
                In the case I described you are trusting the developer at least a bit. But you aren&#x27;t trusting them to keep their website secure.

                Furthermore, you can be sure that theversion that you download is the same version it has always been and it is the same version everyone else sees. Curl|bash can mean getting a version of the code that is different from everybody else.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.