back

by walrus01·1d ago·view on hn ↗
> $ curl -fsSL install.sh | sh # you'd be stupid to run that, slop or not

I wish more people would point this out.

2 comments
I've legitimately seen one project that basically says to do that, but with "your ai agent". At least piping to sh is deterministic and, you can pipe to a filw and check the script

https://github.com/0xeb/ghidrasql

"Claude, install these 215 npm dependencies from unvetted repositores, make no mistakes"
I still haven’t seen anyone point out how this is more dangerous than running an executable that you obtain any other way.
you can detect `curl | bash` server-side and serve a different payload for those (compared to curl -O file, wget etc), hence its an effectively undetectable attack vector.

Executables on the other hand can be inspected and prodded, so the likelihood of something going amiss and consequently security agencies finding out about it is significantly higher.

neither of those is secure of course, we're just discussing different levels of dangers. And curl|bash being worse, albeit not that much

(and the -L here is the extra cherry on top. piping a redirect to a shell is just monkas)

> you can detect `curl | bash` server-side

Oh wow, ok. So if anything, manually do `curl` and `sh` separately?

at that point, i'd put bash script up as being moderately more secure as its generally easier to audit them vs a binary.

but i'Ve also gotta say that random binary download over web is also incredibly rare - usually its either a combination of both (the curl|bash ending in a random binary being downloaded) or the user actually installing via a packagemanager like apt, zypper, yum, dnf etc - and those packagemanagers generally do audit the main repositories, so theyre basically as secure as you can get in those contexts.

but of course, everyone has their own thread model and i dont work in security (●'◡'●)

Because this way does not run security scanners.