Skip to content

Comment on Introducing Pow, a zero-configuration Rack server for Mac OS Xparent

Comments

Anyone who can run a tool to spoof DNS entries can run shell commands on machines that run this installer. Because so few people are going to install Pow relative to the population, I don't want to say this is a gigantic security problem. But the more people use this gimmick, the worse the issue gets.

I think you would be doing the universe a small but meaningful favor not to advertise this installation mechanism.

But it is a very cool tool and a really well-done site. Congrats!

Just as anyone who can spoof DNS entries could swap some other theoretical Pow installer with a malicious one.

I'm not seeing how Pow's installation process is any less secure than, say, downloading a disk image from a random site.

Not if it's served over SSL.

That has nothing to do with whether the installer is a shell script or a binary.

wlllOP

This comment is a repeat, but that may not necessarily be true:

http://www.imperialviolet.org/2011/03/18/revocation.html

Anybody can also spoof DNS entries to point rubygems.org/debian.org/centos.org/redhat.com to a malicious place where the packages contain postinstall scripts that run 'rm -rf /'.

Maybe for rubygems, not so easy for apt/rpm as they use gpg signing/verification of package indices.

RubyGems also have signing facilities. Most authors don't bother signing however because generating a key is too much trouble.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.