← Back to context

Comment by maccard

3 hours ago

What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode

It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it

Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!

And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space

Why is this even an app? It looks like it just generates a mobileconfig profile on the fly. Instead, seems like they could be offering a download of a pre-generated mobileconfig, which seems like it would be much safer than installing some app via curl|bash .... but then I guess there wouldn't be a chance to have an "app", get github stars, and do whatever else.