upvote
Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.
reply
Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
reply
The script, and the code the script downloads, both come from the same repo and were written by the same developer.

If you've already decided you trust the author, what's the actual threat here?

reply
I would not trust the author just like that.

But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.

reply
I think the point is that when a repo contains:

  program.bin
  install.sh
It seems rather pointless for me to thoroughly inspect the install script before I run the program.
reply
You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are
reply
App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft).
reply
[dead]
reply
Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

Its a different threat model. You should not curl bash.

reply
Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get.

But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them.

reply