Turn off Apple Intelligence on macOS 27 and get its disk space back
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Turn off Apple Intelligence on macOS 27 and get its disk space back
Unofficial Hacker News client; not affiliated with Y Combinator.
arialdomartini · · focus · HN ↗
<a href="https://nocurlbash.com/#en" rel="nofollow">https://nocurlbash.com/#en
maccard · · focus · HN ↗
mingus88 · · focus · HN ↗
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
maccard · · focus · HN ↗
You said that, not me. I am not complacent with the security issues, I just don’t believe that the security theatre of “curl | bash” is productive unless you have an actual better alternative.
> they are still better than a curl pipe because they are versioned
pip install is running setup.py which is more than capable of calling exec(requests.get(url)) - except to _you_ that’s secure because you’re assuming it’s trusted. In both cases, if the delivery of the package is compromised or you don’t audit the script, you are screwed. It’s no different to running a binary that you’ve not verified.
zakki · · focus · HN ↗
stock_toaster · · focus · HN ↗