Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I totally agree, and never understood the focus on curly bash script. People seem to be ok to 'git clone; make; sudo make install' something, but hesitate to pipe a remote bash script that comes from the same author, and often is hosted in the exact same repo... At least, nobody ever specifically pointed out how dangerous the make scenario is.

There are a few minor things one should do when writing such a curly bash script, but overall I, personally, don't worry too much about it when I encounter them, I just do my usual security assessment and risk mitigation (which usually does not include reading the code -- that's just not practical).



I think it's the programmer's equivalent of "get off my lawn you kids" or "if you make that face for too long, it'll get stuck like that forever".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: