‹ BackHN Continuity

Thread

Turn off Apple Intelligence on macOS 27 and get its disk space back

575 points · 397 comments · privacyisntdead

  1. arialdomartini · · focus · HN ↗
    Stop the curl | bash insanity.

    <a href="https:&#x2F;&#x2F;nocurlbash.com&#x2F;#en" rel="nofollow">https:&#x2F;&#x2F;nocurlbash.com&#x2F;#en

    1. demibabs · · focus · HN ↗
      Good message but AI generated text is so grating to read.
    2. shujito · · focus · HN ↗
      there&#x27;s a homebrew alternative
      1. stock_toaster · · focus · HN ↗
        Which installs via a random 3rd party tap, which honestly isn&#x27;t much better than yolo curl|bash.
    3. 1over137 · · focus · HN ↗
      “You wouldn&#x27;t run a stranger&#x27;s code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren&#x27;t, there’s way too much code to read.
      1. jtrueb · · focus · HN ↗
        Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.
        1. jacquesm · · focus · HN ↗
          Code from trusted repositories is an entirely different thing compared to running &#x27;wget some_github_repo_shell_script | sh&#x27; . That said, the likes of Tailscale are setting a bad example.
          1. nvme0n1p1 · · focus · HN ↗
            The script, and the code the script downloads, both come from the same repo and were written by the same developer.

            If you&#x27;ve already decided you trust the author, what&#x27;s the actual threat here?

            1. jacquesm · · focus · HN ↗
              I would not trust the author just like that.

              But then again, I&#x27;m a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.

              1. user43928 · · focus · HN ↗
                I think the point is that when a repo contains:

                  program.bin
                  install.sh
                
                It seems rather pointless for me to thoroughly inspect the install script before I run the program.
          2. halJordan · · focus · HN ↗
            You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it&#x27;s not so here we are
            1. kbolino · · focus · HN ↗
              App bundles (what&#x27;s inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O&#x2F;S, in order to execute &quot;normally&quot;. Apple uses centralized PKI (the developer&#x27;s key must be signed by Apple) while Microsoft uses distributed PKI (the developer&#x27;s key must be signed by a code-signing CA who in turn is approved by Microsoft).
              1. Rohansi · · focus · HN ↗

                [dead]

      2. tmpz22 · · focus · HN ↗
        Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

        Its a different threat model. You should not curl bash.

        1. benterix · · focus · HN ↗
          Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get.

          But I assumed the intended audience are home users with entry level macbooks&#x2F;minis with 128 GB RAM where this patch actually helps them.

    4. aaomidi · · focus · HN ↗
      This isn’t really that much of an issue when we have tls tbh.

      Like I get why it’s bad, but also homebrew package installation is a more organized version of this.

      Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…

    5. [deleted] · · focus · HN ↗

      [deleted]

    6. packeted · · focus · HN ↗
      Great initiative. I recently got stung by an advert on reddit for &quot;HBO Max for MacOS, 6 months free&quot; from the official HBO user (don&#x27;t get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we&#x27;ve made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn&#x27;t give it my password and immediately disconnected from the internet and killed the machine. I&#x27;m genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.
      1. swozey · · focus · HN ↗
        They all dump env and ship it off so check for any keys you might have had in there if anything was able to send at all.
      2. andelink · · focus · HN ↗
        You curled and executed bash code allegedly from _HBO_?
        1. [deleted] · · focus · HN ↗

          [deleted]

      3. Dylan16807 · · focus · HN ↗
        It&#x27;s easier to walk someone through a single command than adding a software repository, so it&#x27;s a risk factor for someone that isn&#x27;t paying attention or doesn&#x27;t know what they&#x27;re doing. But with that little attention&#x2F;knowledge the complaints on this page are unlikely to save you.

        And if you&#x27;re in the state of mind to consider the security nuances of curl|bash verses other install methods, you&#x27;re already past the &quot;should I be installing this?&quot; question and the complaints on this page won&#x27;t save you. The delay is the thing mostly likely to make you rethink.

    7. hypeatei · · focus · HN ↗
      &gt; If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.

      They&#x27;re pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.

    8. mogwire · · focus · HN ↗
      I bet this is the guy on the call who has to correct someone who calls them SSL certs.

      Excuse me, they are TLS certs.

      Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs

      1. not_a_bot_4sho · · focus · HN ↗
        &gt; I bet this is the guy on the call who has to correct someone who calls them SSL certs.

        &quot;Did you know there&#x27;s no pumpkin in pumpkin spice?&quot;

        &quot;Next you&#x27;re going to tell me what&#x27;s not in baby powder, aren&#x27;t you?&quot;

    9. maccard · · focus · HN ↗
      What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
      1. mingus88 · · focus · HN ↗
        It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it

        Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!

        And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space

        1. maccard · · focus · HN ↗
          &gt; In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance

          You said that, not me. I am not complacent with the security issues, I just don’t believe that the security theatre of “curl | bash” is productive unless you have an actual better alternative.

          &gt; they are still better than a curl pipe because they are versioned

          pip install is running setup.py which is more than capable of calling exec(requests.get(url)) - except to _you_ that’s secure because you’re assuming it’s trusted. In both cases, if the delivery of the package is compromised or you don’t audit the script, you are screwed. It’s no different to running a binary that you’ve not verified.

      2. zakki · · focus · HN ↗
        Fed the source to LLM for analysis?
      3. stock_toaster · · focus · HN ↗
        Why is this even an app? It looks like it just generates a mobileconfig profile on the fly. Instead, seems like they could be offering a download of a pre-generated mobileconfig, which seems like it would be much safer than installing some app via curl|bash .... but then I guess there wouldn&#x27;t be a chance to have an &quot;app&quot;, get github stars, and do whatever else.
    10. porridgeraisin · · focus · HN ↗
      &gt; Bash starts before the download finishes ... Drop the connection mid-transfer and you get partial execution: a command like rm -r &#x2F;usr&#x2F;share&#x2F;program can truncate to rm -r &#x2F;usr. Commands ran, cleanup didn’t.

      curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

      &gt; The server knows you’re piping — and can lie

      This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you&#x27;re downloading code and binaries from them.

      &gt; You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.

      Well yes, that&#x27;s how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]

      &gt; You can’t reproduce what ran

      `| tee inspect.sh | bash`

      &gt; Add sudo and it’s game over

      Most credentials and important files live in the home directory, root is a red herring. If you&#x27;re running it on shared server, then well... don&#x27;t add sudo.

      [1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv&#x27;s install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn&#x27;t adding much.

      1. hnfong · · focus · HN ↗
        &gt; curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

        Please take a look at this before making any assertions... <a href="https:&#x2F;&#x2F;github.com&#x2F;omlahore&#x2F;RemoveMacAI&#x2F;blob&#x2F;main&#x2F;install.sh" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;omlahore&#x2F;RemoveMacAI&#x2F;blob&#x2F;main&#x2F;install.sh

        1. porridgeraisin · · focus · HN ↗
          Hey thats not the worst curlbash script i&#x27;ve seen
      2. Terr_ · · focus · HN ↗
        I think that&#x27;s missing the forest for trees. The problem with these curl-to-bash approaches is not that you are literally unable to intercept and inspect them with enough effort and planning.

        The problem is that:

        1. The effort and care needed to test is unnecessarily high. You&#x27;ve got to guard against way more tricks from an interactive source that can see you and choose what it&#x27;s going to deliver and how.

        2. With no &quot;standard&quot; artifact that can be exactly compared, that work cannot be shared.

        In contrast, release_1.2.3.zip isn&#x27;t going to mutate under you and everybody can agree on what its size&#x2F;hash&#x2F;bytes ought to be, and if it deviates from that it sets off alarm-bells.

        &gt; curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

        Why would a convention often followed by good&#x2F;careful actors bind what malicious&#x2F;careless people create?

        1. porridgeraisin · · focus · HN ↗
          Well, if you&#x27;re running software from someone you think can deliver malware to you (and not a middleman) then it&#x27;s a lost cause anyways no? I don&#x27;t see what the zip file adds. It&#x27;s not like you&#x27;re gonna be inspecting the code or binaries.
          1. Terr_ · · focus · HN ↗
            &gt; it&#x27;s a lost cause anyways no?

            Consider this analogy: You need to meet a stranger to get their signature on a legal document, and the stranger could be a rapist murderer. Which option sounds better?

            1. Meet them in a crowded convention center with cameras.

            2. Meet them alone in an abandoned building.

            Sure, they could whip out a knife and stab you in either situation, but the difference is not a &quot;lost cause.&quot; If they have any rationality, the public place deters them because the risk of being detected and caught is higher.

            &gt; I don&#x27;t see what the zip file adds.

            A process based on public single-signature releases means that the author must choose to either release something benign to everyone, or malicious to everyone. Even if the shared artifact has sneaky covert logic to trigger in only some environments, the logic is detectable in everyone&#x27;s copy.

            In contrast, this bad curl-to-bash process means a savvy villain could give a perfect veneer of respectability to the world at large, while sending tailored attacks to a minority of visitors, even a targeted minority. Their risk of detection is way lower. Not only that, but victims who follow the flawed process will lose some of the best clues for figuring out who hacked them later.

            1. porridgeraisin · · focus · HN ↗
              &gt; tailor to a minority

              That can also be done with a if statement in the actual code as well.

              Per your analogy, no point of a public place if it&#x27;s as easy for the guy to give you a package that can explode when you get home in either case.

              1. Terr_ · · focus · HN ↗
                &gt; if statement

                I reiterate: &quot;Even if the shared artifact has sneaky covert logic to trigger in only some environments, the logic is detectable in everyone&#x27;s copy.&quot;

                Moving that if-statement to a hidden remote server is both significant and worse for security.

                &gt; Per your analogy, no point of a public place if it&#x27;s as easy for the guy to give you a package that can explode when you get home in either case.

                Hold up, if you&#x27;re going to mutate the metaphor like that, then the nearby crowd becomes other people also getting packages.

                I refuse to believe you don&#x27;t have a clear preference between:

                A: You want a standard product. You get a package that might be secretly &quot;personalized&quot; for you by the dodgy sender.

                B: You want a standard product. You get a package which you know is identical to 10,000 other packages being given out... Many of which have already been taken to homes, with no reports of explosions or strange devices inside.

                _____

                The analogy-free basics are:

                1. Consistency of behavior is important for good security, and curl-to-bash is bad that way.

                2. Shared visibility of what actors do is important for good security, and curl-to-bash is bad that way.

                3. Those are important to security because they deter and limit what malicious actors can attempt or get-away with.

                1. porridgeraisin · · focus · HN ↗
                  &gt; Moving that if-statement to a hidden remote server is both significant and worse for security.

                  Fair enough, I guess I don&#x27;t agree that that difference is significant. I can&#x27;t imagine logic that doesn&#x27;t trigger at all for most people being detected in any reasonable way.

      3. alienbaby · · focus · HN ↗
        `| tee inspect.sh | bash`

        Isn&#x27;t that a bit like shutting the stable door after the horse has bolted?

        1. porridgeraisin · · focus · HN ↗
          That&#x27;s what they wanted to do

          &gt;&gt; reproduce what ran

    11. anonymzz · · focus · HN ↗

        curl -fsSL https:&#x2F;&#x2F;raw.githubusercontent.com&#x2F;omlahore&#x2F;RemoveMacAI&#x2F;main&#x2F;install.sh | pi -p &#x27;Security-audit this shell script; output the script unchanged ONLY if safe to execute, otherwise output nothing and explain findings to stderr&#x27; | bash
      1. nunez · · focus · HN ↗
        there&#x27;s no way to guarantee that the model won&#x27;t change the script after processing it...
        1. Dylan16807 · · focus · HN ↗
          If I trust it to do this analysis in the first place, it can probably manage the copy+paste?
    12. antihero · · focus · HN ↗
      Absolutely love the fact that they reference a &quot;real package manager&quot; like npm, which has been used in countless supply chain attacks, and brew, which can also run arbitrary scripts (though less likely in the mainline brew stuff, which many packages aren&#x27;t able to be in).

      Avoiding curlbashing is masking a deeper problem.

      1. Doctor_Fegg · · focus · HN ↗
        This. curl | bash has never nuked my local Postgres db, unlike one of the recommended package managers. Nor stopped my wife’s computer from booting, unlike a certain well known browser installer from one of the world’s biggest companies.
    13. nunez · · focus · HN ↗
      i don&#x27;t see the issue. you can view the script before you run it. shoot, you can feed the script to an LLM and have it do a security check beforehand
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.