logoalt Hacker News

deadbunny • today at 1:33 PM • 4 replies • view on HN

> Set up Strata on this PC for me: https://github.com/Niko1221/Strata - follow docs/AI_SETUP.md in that repository.

And I thought piping to bash was bad


Replies

Skunkleton • today at 3:05 PM

I've never understood the security argument people are making when they complain about `curl foo | bash`. I get that these scripts sometimes mess up your bashrc or whatever, but from a security perspective I see no issue. You are already installing software from the same domain. If they were going to do something nasty, they could do it with any of the software you are using from them. It doesn't have to be the setup script.

➕ show 10 replies
gchamonlive • today at 1:46 PM

Piping to bash is definitely worse because there is no plan mode in bash. Agents also normally don't execute anything transparently, at worst you'll see it doing something weird in the logs.

snehesht • today at 1:34 PM

Yeah, I was surprised at first then had to dig through setup.py and setup.sh files to figure out.

mrinterweb • today at 5:51 PM

And yet people will let AI agents run autonomously on their machines. I feel like we're reaching peak YOLO with security.