upvote
I don't see what the issue is, my agent is already running as root.
reply
Yeah it has all the government logins and full gmail access. It will be too busy to bother rooting the local machine!
reply
Shouldn't be a problem, we're currently clean on OpSec.
reply
Good thing we haven't normalized installing things with curl | sh
reply
Yeah, that's great!

Imagine we would download random code from the internet and just execute it, like with NPM, PIP, Maven, Cargo etc.

reply
cargo/uv/go have lock files though
reply
with curl | sh you could use a checksum you download with curl!
reply
I don’t think that matters as it’s usually curl | sudo sh
reply
Or npm being allowed to run arbitrary post install scripts
reply
I literally ship an installer that runs with curl | bash... reading this thread while patching my servers is a fun experience lol
reply
[dead]
reply