curl https://some-url | sh

I see this all over the place nowadays, even in communities that, I would think, should be security conscious. How is that safe? What’s stopping the downloaded script from wiping my home directory? If you use this, how can you feel comfortable?

I understand that we have the same problems with the installed application, even if it was downloaded and installed manually. But I feel the bar for making a mistake in a shell script is much lower than in whatever language the main application is written. Don’t we have something better than “sh” for this? Something with less power to do harm?

  • Taasz/Woof
    link
    fedilink
    English
    17
    edit-2
    2 years ago

    It’s not much different from downloading and compiling source code, in terms of risk. A typo in the code could easily wipe home or something like that.

    Obviously the package manager repo for your distro is the best option because there’s another layer of checking (in theory), but very often things aren’t in the repos.

    The solution really is just backups and snapshots, there are a million ways to lose files or corrupt them.

    • Possibly linux
      link
      fedilink
      English
      02 years ago

      You should use officially packaged software. That’s the safest option.

        • Possibly linux
          link
          fedilink
          English
          02 years ago

          Debian has 60,425 packages. I would recommend that you create a Debian container with distrobox and install whatever you need. If you need newer versions you can use Debian Sid.

          • Taasz/Woof
            link
            fedilink
            English
            02 years ago

            Yeah it’s often missing CLI tools that are from small devs who can’t do packaging.