• atzanteol@sh.itjust.works
    link
    fedilink
    arrow-up
    25
    ·
    2 months ago

    Copy Fail requires only an unprivileged local user account — no network access, no kernel debugging features, no pre-installed primitives

    Which is a fairly high hurdle for an attacker in most instances. Unless you’re running something like a shared university server.

    Definitely patch your systems though.

    • Aganim@lemmy.world
      link
      fedilink
      arrow-up
      15
      ·
      edit-2
      2 months ago

      Which is a fairly high hurdle for an attacker in most instances.

      With software projects training people that curl <link to their install script> | bash is totally fine and the insane amount of supply chain attacks lately it’s a critical bug that’s just begging to be exploited on single user systems.

      So yes, patch your systems and definitely do not downplay this.

      • atzanteol@sh.itjust.works
        link
        fedilink
        arrow-up
        6
        ·
        2 months ago

        With software projects training people that curl <link to their install script> | bash is totally fine and the insane amount of supply chain attacks lately it’s a critical bug that’s just begging to be exploited on single user systems.

        I wish the worst case of gout on people who do this. I can’t believe it’s become such an accepted way of installing software.

        • HaraldvonBlauzahn@feddit.org
          link
          fedilink
          arrow-up
          1
          ·
          7 days ago

          It is still the recommended way to install Rust… M)

          But what is bonkers is that pip install can run arbitrary code. The python packaging system is likely to be the next target of such attackers.

        • moopet@sh.itjust.works
          link
          fedilink
          arrow-up
          8
          ·
          2 months ago

          I have a vague memory of some project that did this ages ago where you could see the script on their web page but when you ran the command it executed a different script (there was a single-character difference in the URL) and the result was it told you not to be so dumb as to run scripts like that.