‹ BackHN Continuity

Thread

Turn off Apple Intelligence on macOS 27 and get its disk space back

594 points · 406 comments · privacyisntdead

  1. arialdomartini · · focus · HN ↗
    Stop the curl | bash insanity.

    <a href="https:&#x2F;&#x2F;nocurlbash.com&#x2F;#en" rel="nofollow">https:&#x2F;&#x2F;nocurlbash.com&#x2F;#en

    1. maccard · · focus · HN ↗
      What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
      1. mingus88 · · focus · HN ↗
        It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it

        Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!

        And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space

        1. maccard · · focus · HN ↗
          &gt; In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance

          You said that, not me. I am not complacent with the security issues, I just don’t believe that the security theatre of “curl | bash” is productive unless you have an actual better alternative.

          &gt; they are still better than a curl pipe because they are versioned

          pip install is running setup.py which is more than capable of calling exec(requests.get(url)) - except to _you_ that’s secure because you’re assuming it’s trusted. In both cases, if the delivery of the package is compromised or you don’t audit the script, you are screwed. It’s no different to running a binary that you’ve not verified.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.