ChanServ changed the topic of #sandstorm to: Welcome to #sandstorm: home of all things Sandstorm and Cap'n Proto. Say hi! | Have a question but no one is here? Try asking in the discussion group: https://groups.google.com/group/sandstorm-dev | Channel logs available at https://libera.irclog.whitequark.org/sandstorm
<ocdtrekkie> I just can't help myself with chatting in GitHub issues. :/
<ocdtrekkie> Hiding comments makes me feel better about it though, still easy for people to expand and read.
jfred_ is now known as jfred
isd has quit [Quit: Bridge terminating on SIGTERM]
abliss has quit [Quit: Bridge terminating on SIGTERM]
ocdtrekkie has quit [Quit: Bridge terminating on SIGTERM]
timmc[m] has quit [Quit: Bridge terminating on SIGTERM]
jryans has quit [Quit: Bridge terminating on SIGTERM]
koo7 has joined #sandstorm
koo7 has quit [Ping timeout: 256 seconds]
TMM_ has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
TMM_ has joined #sandstorm
koo7 has joined #sandstorm
koo7 has quit [Ping timeout: 256 seconds]
koo7 has joined #sandstorm
koo7 has quit [Ping timeout: 256 seconds]
xet7 has quit [Remote host closed the connection]
xet7 has joined #sandstorm
xet7 has quit [Remote host closed the connection]
xet7 has joined #sandstorm
xet7 has quit [Remote host closed the connection]
xet7 has joined #sandstorm
koo7 has joined #sandstorm
koo7 has quit [Ping timeout: 268 seconds]
koo7 has joined #sandstorm
stdedos has joined #sandstorm
<stdedos> Hello there! I am reading https://sandstorm.io/news/2015-09-24-is-curl-bash-insecure-pgp-verified-install, and I was wondering about this part:
<stdedos> > If you wish to install Sandstorm – or any software – without giving it full access to your system, you must install it on a dedicated machine, VM, or (perhaps, with caveats) user account. In fact, we highly encourage you to do so, for defense in depth. But, we know it’s more work than a lot of people want to deal with.
<stdedos> Are there instructions for an "installation on a dedicated user account"?
<stdedos> Also, for the sake of the article above, the following links https://news.ycombinator.com/item?id=12766350, https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ might interest you to somehow look at them for the sake of completeness
<stdedos> In any case, +1 from me for giving out a PGP-terifying alternative
isd has joined #sandstorm
isd has left #sandstorm [#sandstorm]
isd1 has joined #sandstorm
<isd1> stdedos: re: dedicated user account, that's going to depend on the software, and probably won't do much good for Sandstorm, since it needs a fair amount of access anyway
<isd1> (I think it's technically possible to run it without root using user namespaces, but it needs a bunch of APIs that we deny grains access to for a reason... so I'd be squeamish about relying on it).
<stdedos> isd1 ... aka docker then?
stdedos has quit [Quit: Client closed]
jryans has joined #sandstorm
isd has joined #sandstorm
ocdtrekkie has joined #sandstorm
timmc[m] has joined #sandstorm
abliss has joined #sandstorm
jryans has quit [Quit: node-irc says goodbye]
ocdtrekkie has quit [Quit: node-irc says goodbye]
isd has quit [Quit: node-irc says goodbye]
timmc[m] has quit [Quit: node-irc says goodbye]
abliss has quit [Quit: node-irc says goodbye]
TMM_ has quit [Quit: https://quassel-irc.org - Chat comfortably. Anywhere.]
TMM_ has joined #sandstorm
jryans has joined #sandstorm
isd has joined #sandstorm
ocdtrekkie has joined #sandstorm
timmc[m] has joined #sandstorm
abliss has joined #sandstorm
isd1 has quit [Quit: Leaving.]
koo7 has quit [Ping timeout: 272 seconds]