Comment by 1over137

4 hours ago

“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.

Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.

  • Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.

    • The script, and the code the script downloads, both come from the same repo and were written by the same developer.

      If you've already decided you trust the author, what's the actual threat here?

      2 replies →

    • You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are

      2 replies →

Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

Its a different threat model. You should not curl bash.

  • Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get.

    But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them.