People are afraid of running unaudited `curl | sh`, but nobody bats an eye on 24707 lines of obfuscated garbage in `./configure`.
Conversation
Notices
-
Embed this notice
Kornel (kornel@mastodon.social)'s status on Monday, 01-Apr-2024 03:49:09 JST Kornel
- GreenSkyOverMe (Monika) repeated this.
-
Embed this notice
Kornel (kornel@mastodon.social)'s status on Monday, 01-Apr-2024 03:49:09 JST Kornel
Seriously, in retrospect, #autotools itself is a massive supply-chain security risk.
It has normalized shipping and running tens of thousands of lines of arbitrary executable code without any safeguards.
Code that is so mind-numbingly awful that nobody will review it, and written in a language that is full of gotchas that are sneaky eval gadgets.