‹ BackHN Continuity

Thread

Turn off Apple Intelligence on macOS 27 and get its disk space back

515 points · 323 comments · privacyisntdead

  1. arialdomartini · · focus · HN ↗
    Stop the curl | bash insanity.

    <a href="https:&#x2F;&#x2F;nocurlbash.com&#x2F;#en" rel="nofollow">https:&#x2F;&#x2F;nocurlbash.com&#x2F;#en

    1. 1over137 · · focus · HN ↗
      “You wouldn&#x27;t run a stranger&#x27;s code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren&#x27;t, there’s way too much code to read.
      1. jtrueb · · focus · HN ↗
        Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.
        1. jacquesm · · focus · HN ↗
          Code from trusted repositories is an entirely different thing compared to running &#x27;wget some_github_repo_shell_script | sh&#x27; . That said, the likes of Tailscale are setting a bad example.
          1. nvme0n1p1 · · focus · HN ↗
            The script, and the code the script downloads, both come from the same repo and were written by the same developer.

            If you&#x27;ve already decided you trust the author, what&#x27;s the actual threat here?

            1. jacquesm · · focus · HN ↗
              I would not trust the author just like that.

              But then again, I&#x27;m a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.

              1. user43928 · · focus · HN ↗
                I think the point is that when a repo contains:

                  program.bin
                  install.sh
                
                It seems rather pointless for me to thoroughly inspect the install script before I run the program.
          2. halJordan · · focus · HN ↗
            You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it&#x27;s not so here we are
            1. kbolino · · focus · HN ↗
              App bundles (what&#x27;s inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O&#x2F;S, in order to execute &quot;normally&quot;. Apple uses centralized PKI (the developer&#x27;s key must be signed by Apple) while Microsoft uses distributed PKI (the developer&#x27;s key must be signed by a code-signing CA who in turn is approved by Microsoft).
              1. Rohansi · · focus · HN ↗

                [dead]

      2. tmpz22 · · focus · HN ↗
        Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

        Its a different threat model. You should not curl bash.

        1. benterix · · focus · HN ↗
          Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get.

          But I assumed the intended audience are home users with entry level macbooks&#x2F;minis with 128 GB RAM where this patch actually helps them.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.