Nope. The only people who notice or care about any of this are those who can't accommodate the storage. Outside that, it all just works better now (especially Siri).
I'm sick of juggling disk space on my 1tb laptop AND I don't want an llm attack vector anywhere near my machine, this things getting nuked from orbit or i'm not updating to golden gate, ever.
Oh, things are about to get worse with the new macOS "privacy/security" measures. They are going to curb agentic workflows even more. I don't know how Apple just finds new ways to annoy developers, but we're in a minority after all. Of 200 million Mac users, probably just up to 1 million are developers, and the rest are normies who can't tell when they should authorize or cancel the pop-up.
They love the ones that buy Apple hardware to develop apps for iDevices, pay the dev subscription and store fees for apps, or simply because they wanted a shiny UNIX and don't consider BSD/Linux OEMs worth their money.
“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.
Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.
What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
> If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.
They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.
What's going on at Apple product strategy?
GNOME has reached maturity and hasn't changed significantly in years, while Apple is busy destroying macOS.
https://nocurlbash.com/#en
Its a different threat model. You should not curl bash.
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
Excuse me, they are TLS certs.
Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs
Like I get why it’s bad, but also homebrew package installation is a more organized version of this.
Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…
They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.