I no longer have a Mac as I’ve moved over to Linux, but my iOS device leaves me very frustrated that I can no longer disable this AI stuff with a simple toggle.
It seems insane given that Apple’s competitors (Microsoft, Firefox, probably others) moved toward a global AI switch to make the choice easy for their customers.
Reminds me of all the de-crufting you've always needed to do when you install Windows. Looks like we've gotten to the point on macOS too, where you need to run third party scripts on a new OS installation to gain back control of your system resources and remove unwanted crapware.
Automatically downloading AI models into disk space with no user-facing way to turn it off is especially hostile considering Apple as vendor of both the OS and the hardware is the same entity that overcharges for non-upgradable SSD storage in their machines.
People have been doing the same thing with Cortana on Windows for ages. "Debloating" tools don't primarily target OEM add-ons like free trials of this or that; they very much target Windows components.
Fully functional feature consuming multiple gigabytes of storage and has questionable functional value. Maybe people don't want bloated AI crap on their desktops?
I’m not making any judgement on whether you should or should not like the feature.
I’m stating that the Windows problem was very different. Your machine would be loaded up with software for various vendors that the manufacturer did deals with to lower the price of the machine. They were all trials.
On Windows there are lots of fully features features/applications people turn off. It's not all trial versions and it's disingenuous to pretend it's just that.
The new spotlight search replaced what I previously used, made it function worse for what I used it for, and uses 30GiB of already very scarce disk space.
For many users, it is a strict downgrade that was forced on them against their consent.
True that, win11debloat is 'mandatory' nowadays.
The time that OS makers competed with each other with features users actually wanted is long gone, alas..
This is why Linux is now making more serious momentum. Even a long term 'Microsoftie' like myself is now standing on the brink of making the leap. Just a bit more Steam compatibility first please...
I got an old disk with a win10 installation on it. It lasted only three days. It was because of all the pinging from notifications and all the CTA buttons (like Sign in to Onedrive in the settings). It felt like a minefield where a click can blow your whole setup.
I wipe the whole thing and installed Fedora.
I could tolerate windows if I needed a particular set of software on it, but no way that I could use it as a daily driver.
It's interesting to see more customisation tools appearing for macOS, as just a few years ago I was looking for ways to strip down the OS (CI related), and while such info was widely available in the Windows world, to the point that customised "distros" are available, it was nearly nonexistent for macOS; only the Hackintosh community had some useful articles on how things worked.
Could the rise of LLMs and vibe-coding have motivated people who otherwise wouldn't bother?
It’s hard to strip it down these days as the OS image and its core, immutable filesystem cannot be edited. Admittedly this helps keep idiots from destroying their filesystem and also blocks many malware attacks on the system, but, for example. I don’t believe you can delete the chess program.
and its core, immutable filesystem cannot be edited
That's a half-truth at best; I can just open the disk image in a hex editor if nothing else understands the format.
Hackintoshers have figured out how to add/modify drivers etc. It's certainly not without obstacles, but that's still very far from "impossible". If I remember correctly, you need to re-snapshot the FS and tell the bootloader to boot from it.
(And necessarily, ignoring the countless cries of "it can't be done" was how I was able to accomplish my goal... I knew that it was possible since I could edit any bit of the FS; figuring out which files I could remove and patch was the hard and undocumented part.)
This is one of those things where you have to ask yourself "how do you get it so wrong?". I get the idea of protecting from malware/self-harm, but to not allow removal of such a pointless app is just befuddling. At least Microsoft trying to say that Explorer was core to the OS, but a chess app? I never did buy into Explorer being core until the day I accidentally pasted an URL into File Explorer's path and it rendered the webpage. I don't understand why someone thought that was necessary to allow to happen, but there it was, core to the OS.
I think it’s because all those apps use core technologies so their bundle size is tiny. You hide them and never think about them (like the old windows media player). Most of windows optional features are very much in your face all the time.
Apple was late to the AI party. Usually, that's their strategy - let everyone else innovate, when the ecosystem is mature, steal it and claim it as their own. That worked well for decades. But, the pace of AI is too fast to pull this trick off again, so now they're in panic mode. So they do what every shitty corporate does - shove AI down everyone's throat, whether they want it or not. Which is ironically against their founder's motto - build stuff that people want.
I'm not sure there were enough people looking at finder and thinking "I wish I could talk to an AI to open a file on my desktop which I could've simply double clicked on anyway"
The enshittification of Apple is going on. Debloating Windows, degoogling Android. MacOS/iOS was still decent a few months ago. And now they've put banners on iPhones, real advertisements trying to force you to subscribe to Apple This, Apple That. And you can't close the banner. Now they remove the option for you to remove the models. And Apple storage space is darn expensive. Now we have to use a 3rd-party tool to debloat Apple's OS too? To hell with that. Is this really the year to go full-time Linux? Steve must be squirming down there with the enshittification of Apple too. Let's shove AI (SI is different stuff, Bozo) down your throats. Jesus Christ. I suppose that's what the board members want. More revenue. Maybe it's time to start parting ways with Apple if they keep it like that. Corporate greed has taken over and user experience has gone down the drain.
Ihave three screenshots on my iPhone taken two weeks apart. I have one point Apple Intelligence, while it’s turned off mind you, takes up four gigs of space, then it disappeared, and now it’s back to four gigs again. Can someone please explain this to me?
Not a lot of good reasons to upgrade to 27. They removed Rosetta and you have to reinstall that if you want it. So is MacOS turning into something that more regular people are going to have to maintain in the future or end up with something like Windows 11?
I switched to MacOS 3 years ago because of Microsoft and the writing on the wall seems to say I got another year left before I'm forced into Linux. Because if I have to maintain my own OS then I might as well install Linux and do it once.
If a temporary tool being retired is the reason you switch, then wait until you find out how many LOC are being deleted from the linux kernel this year and next
The alternative is maintaining backwards compatibility forever and then everyone will complain about some weird behaviour that still happens to retain that compatibility.
Keep in mind this is the second time they have switched arches and the second round of complaints of Rosetta removal.
That doesn't seem to do much in the `curl | bash` setting, given that you're not verifying the attestation in that case. You still need to download it separately and run `gh attestation verify` first.
(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)
“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.
Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are
App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft).
But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.
Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.
curl -fsSL https://raw.githubusercontent.com/omlahore/RemoveMacAI/main/install.sh | pi -p 'Security-audit this shell script; output the script unchanged ONLY if safe to execute, otherwise output nothing and explain findings to stderr' | bash
What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
Why is this even an app? It looks like it just generates a mobileconfig profile on the fly. Instead, seems like they could be offering a download of a pre-generated mobileconfig, which seems like it would be much safer than installing some app via curl|bash .... but then I guess there wouldn't be a chance to have an "app", get github stars, and do whatever else.
> Bash starts before the download finishes ... Drop the connection mid-transfer and you get partial execution: a command like rm -r /usr/share/program can truncate to rm -r /usr. Commands ran, cleanup didn’t.
curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
> The server knows you’re piping — and can lie
This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.
> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.
Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]
> You can’t reproduce what ran
`| tee inspect.sh | bash`
> Add sudo and it’s game over
Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.
[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.
I think that's missing the forest for trees. The problem with these curl-to-bash approaches is not that you are literally unable to intercept and inspect them with enough effort and planning.
The problem is that:
1. The effort and care needed to test is unnecessarily high. You've got to guard against way more tricks from an interactive source that can see you and choose what it's going to deliver and how.
2. With no "standard" artifact that can be exactly compared, that work cannot be shared.
In contrast, release_1.2.3.zip isn't going to mutate under you and everybody can agree on what its size/hash/bytes ought to be, and if it deviates from that it sets off alarm-bells.
> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
Why would a convention often followed by good/careful actors bind what malicious/careless people create?
Well, if you're running software from someone you think can deliver malware to you (and not a middleman) then it's a lost cause anyways no? I don't see what the zip file adds. It's not like you're gonna be inspecting the code or binaries.
> If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.
They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.
Another thing that bit me is that automatic updates reserve disk space even if no update is available. It makes sense when you have plenty of disk space but on my MacBook Air with 256gb of storage it was about 10% that I got back after turning off automatic updates. I’ll get a Mac with more storage next time so I don’t have to do that.
Oh, things are about to get worse with the new macOS "privacy/security" measures. They are going to curb agentic workflows even more. I don't know how Apple just finds new ways to annoy developers, but we're in a minority after all. Of 200 million Mac users, probably just up to 1 million are developers, and the rest are normies who can't tell when they should authorize or cancel the pop-up.
It’s not about privacy, it’s about kneecapping competitors, just like when they blocked the advertising ID but exempted themselves from this because “Apple is not a third-party, we’re a second-party”.
Apple is an advertising company and thus inherently untrustworthy.
They love the ones that buy Apple hardware to develop apps for iDevices, pay the dev subscription and store fees for apps, or simply because they wanted a shiny UNIX and don't consider BSD/Linux OEMs worth their money.
Really? GNOME is not what I would recommend to people.
I should applaud their efforts, and I get that much of it is voluntary, but their bugs are numerous, notable and the way they interact with the rest of the universe (both people with accessibility needs, and the wider developer ecosystem on linux) can most accurately be described as arrogant and hostile.
KDE is the bastion of maturity here, and I would agree that it is mature.
I’m not sure how the love for GNOME continues when KDE (while not my personal choice) has clearly been running circles around it since GNOME3 and the gap has only widened since that change too.
Both desktops are pretty mature. I've run both of their Wayland stacks, and Mutter/KWin both perform great these days. It really comes down to personal preference for most use-cases.
I first saw it with Homebrew over a decade ago. It made it more linux, it's true. (Of course now that its for linuxes too, so they get to be more like macs.)
I see archive.today has the charming old ruby version on the bottom of a 2013 brew.sh page in 2013, when I must first have used it https://archive.ph/lCqJ1
Nope. The only people who notice or care about any of this are those who can't accommodate the storage. Outside that, it all just works better now (especially Siri).
Also "those who can't accommodate the storage" is funny.
What's that? You didn't pay Apple's 1200% markup on storage, just so you can have enough room for your actual work after the OS fills your disk with a bunch of bloat? What are you, poor?
I'm sick of juggling disk space on my 1tb laptop AND I don't want an llm attack vector anywhere near my machine, this things getting nuked from orbit or i'm not updating to golden gate, ever.
I no longer have a Mac as I’ve moved over to Linux, but my iOS device leaves me very frustrated that I can no longer disable this AI stuff with a simple toggle.
It seems insane given that Apple’s competitors (Microsoft, Firefox, probably others) moved toward a global AI switch to make the choice easy for their customers.
I don't understand why you would want to remove well-balanced and relatively small local-inference models that ship with every mac.
Sure, not frontier levels but fine for basic tasks and they are off-the-cloud.
Reminds me of all the de-crufting you've always needed to do when you install Windows. Looks like we've gotten to the point on macOS too, where you need to run third party scripts on a new OS installation to gain back control of your system resources and remove unwanted crapware.
On windows you got garbage like trial versions of Blah software.
This is a fully functioning feature that people don’t like for what ever reason.
Automatically downloading AI models into disk space with no user-facing way to turn it off is especially hostile considering Apple as vendor of both the OS and the hardware is the same entity that overcharges for non-upgradable SSD storage in their machines.
People have been doing the same thing with Cortana on Windows for ages. "Debloating" tools don't primarily target OEM add-ons like free trials of this or that; they very much target Windows components.
Cortana was heavily integrated with bing
I just don't use it. I'm on a laptop with 500gb. I don't want to lose on so much disk space for a feature I won't use.
Fully functional feature consuming multiple gigabytes of storage and has questionable functional value. Maybe people don't want bloated AI crap on their desktops?
I’m not making any judgement on whether you should or should not like the feature.
I’m stating that the Windows problem was very different. Your machine would be loaded up with software for various vendors that the manufacturer did deals with to lower the price of the machine. They were all trials.
"fully functioning feature" -- more like full functioning forceware/crapware which holds significant space.
so it's not for "what ever reason", it's quite a reason to reject this.
On Windows there are lots of fully features features/applications people turn off. It's not all trial versions and it's disingenuous to pretend it's just that.
IE is also a fully functioning feature, so are snap packages.
This will always be the case with proprietary software, invariably. Just a matter of time.
What makes you call it crapware? The new spotlight search (from Siri) is amazing and super convenient.
I don’t want to make my search more ambiguous. That is the opposite of what I want.
The new spotlight search replaced what I previously used, made it function worse for what I used it for, and uses 30GiB of already very scarce disk space.
For many users, it is a strict downgrade that was forced on them against their consent.
Can it now consistently find things in /Applications when I type the full name?
That's revolutionary.
True that, win11debloat is 'mandatory' nowadays. The time that OS makers competed with each other with features users actually wanted is long gone, alas.. This is why Linux is now making more serious momentum. Even a long term 'Microsoftie' like myself is now standing on the brink of making the leap. Just a bit more Steam compatibility first please...
I got an old disk with a win10 installation on it. It lasted only three days. It was because of all the pinging from notifications and all the CTA buttons (like Sign in to Onedrive in the settings). It felt like a minefield where a click can blow your whole setup.
I wipe the whole thing and installed Fedora.
I could tolerate windows if I needed a particular set of software on it, but no way that I could use it as a daily driver.
This is stuff on the level of O&O ShutUp10. Which is a good tool, but also, a Windows tool for very (back in the day) Windows-specific nonsense.
What's going on at Apple product strategy?
It's interesting to see more customisation tools appearing for macOS, as just a few years ago I was looking for ways to strip down the OS (CI related), and while such info was widely available in the Windows world, to the point that customised "distros" are available, it was nearly nonexistent for macOS; only the Hackintosh community had some useful articles on how things worked.
Could the rise of LLMs and vibe-coding have motivated people who otherwise wouldn't bother?
It’s hard to strip it down these days as the OS image and its core, immutable filesystem cannot be edited. Admittedly this helps keep idiots from destroying their filesystem and also blocks many malware attacks on the system, but, for example. I don’t believe you can delete the chess program.
and its core, immutable filesystem cannot be edited
That's a half-truth at best; I can just open the disk image in a hex editor if nothing else understands the format.
Hackintoshers have figured out how to add/modify drivers etc. It's certainly not without obstacles, but that's still very far from "impossible". If I remember correctly, you need to re-snapshot the FS and tell the bootloader to boot from it.
(And necessarily, ignoring the countless cries of "it can't be done" was how I was able to accomplish my goal... I knew that it was possible since I could edit any bit of the FS; figuring out which files I could remove and patch was the hard and undocumented part.)
This is one of those things where you have to ask yourself "how do you get it so wrong?". I get the idea of protecting from malware/self-harm, but to not allow removal of such a pointless app is just befuddling. At least Microsoft trying to say that Explorer was core to the OS, but a chess app? I never did buy into Explorer being core until the day I accidentally pasted an URL into File Explorer's path and it rendered the webpage. I don't understand why someone thought that was necessary to allow to happen, but there it was, core to the OS.
I think it’s because all those apps use core technologies so their bundle size is tiny. You hide them and never think about them (like the old windows media player). Most of windows optional features are very much in your face all the time.
Why would you expect Apple X strategy to be different from Microsoft X strategy?
Apple was late to the AI party. Usually, that's their strategy - let everyone else innovate, when the ecosystem is mature, steal it and claim it as their own. That worked well for decades. But, the pace of AI is too fast to pull this trick off again, so now they're in panic mode. So they do what every shitty corporate does - shove AI down everyone's throat, whether they want it or not. Which is ironically against their founder's motto - build stuff that people want.
I'm not sure there were enough people looking at finder and thinking "I wish I could talk to an AI to open a file on my desktop which I could've simply double clicked on anyway"
The enshittification of Apple is going on. Debloating Windows, degoogling Android. MacOS/iOS was still decent a few months ago. And now they've put banners on iPhones, real advertisements trying to force you to subscribe to Apple This, Apple That. And you can't close the banner. Now they remove the option for you to remove the models. And Apple storage space is darn expensive. Now we have to use a 3rd-party tool to debloat Apple's OS too? To hell with that. Is this really the year to go full-time Linux? Steve must be squirming down there with the enshittification of Apple too. Let's shove AI (SI is different stuff, Bozo) down your throats. Jesus Christ. I suppose that's what the board members want. More revenue. Maybe it's time to start parting ways with Apple if they keep it like that. Corporate greed has taken over and user experience has gone down the drain.
Ihave three screenshots on my iPhone taken two weeks apart. I have one point Apple Intelligence, while it’s turned off mind you, takes up four gigs of space, then it disappeared, and now it’s back to four gigs again. Can someone please explain this to me?
How do we believe this tool? Is it secure?
It’s open source, go find out and report back.
Is there a way to do this manually?
https://discussions.apple.com/docs/DOC-250012366
Not a lot of good reasons to upgrade to 27. They removed Rosetta and you have to reinstall that if you want it. So is MacOS turning into something that more regular people are going to have to maintain in the future or end up with something like Windows 11?
I switched to MacOS 3 years ago because of Microsoft and the writing on the wall seems to say I got another year left before I'm forced into Linux. Because if I have to maintain my own OS then I might as well install Linux and do it once.
Nearly everything is improved and the new Siri is great.
Unless you're not running a M-series chip, then it's not really improving anything
If a temporary tool being retired is the reason you switch, then wait until you find out how many LOC are being deleted from the linux kernel this year and next
It's not a temporary tool for people who need it.
The alternative is maintaining backwards compatibility forever and then everyone will complain about some weird behaviour that still happens to retain that compatibility.
Keep in mind this is the second time they have switched arches and the second round of complaints of Rosetta removal.
I think they have a lot more reason to keep it around this time. PowerPC was a dead-end and x86 is most definitely sticking around.
> Every release is built from its tag by GitHub Actions and carries a build provenance attestation.
Huh cool. They're doing curl | bash properly.
That doesn't seem to do much in the `curl | bash` setting, given that you're not verifying the attestation in that case. You still need to download it separately and run `gh attestation verify` first.
(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)
This should have been a prompt.
Stop the curl | bash insanity.
https://nocurlbash.com/#en
“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.
Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.
Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are
App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft).
The script, and the code the script downloads, both come from the same repo and were written by the same developer.
If you've already decided you trust the author, what's the actual threat here?
I would not trust the author just like that.
But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.
I think the point is that when a repo contains:
It seems rather pointless for me to thoroughly inspect the install script before I run the program.Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.
Its a different threat model. You should not curl bash.
Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get.
But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them.
Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.
You curled and executed bash code allegedly from _HBO_?
They all dump env and ship it off so check for any keys you might have had in there if anything was able to send at all.
Good message but AI generated text is so grating to read.
What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
Fed the source to LLM for analysis?
Why is this even an app? It looks like it just generates a mobileconfig profile on the fly. Instead, seems like they could be offering a download of a pre-generated mobileconfig, which seems like it would be much safer than installing some app via curl|bash .... but then I guess there wouldn't be a chance to have an "app", get github stars, and do whatever else.
I bet this is the guy on the call who has to correct someone who calls them SSL certs.
Excuse me, they are TLS certs.
Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs
there's a homebrew alternative
Which installs via a random 3rd party tap, which honestly isn't much better than yolo curl|bash.
> Bash starts before the download finishes ... Drop the connection mid-transfer and you get partial execution: a command like rm -r /usr/share/program can truncate to rm -r /usr. Commands ran, cleanup didn’t.
curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
> The server knows you’re piping — and can lie
This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.
> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.
Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]
> You can’t reproduce what ran
`| tee inspect.sh | bash`
> Add sudo and it’s game over
Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.
[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.
`| tee inspect.sh | bash`
Isn't that a bit like shutting the stable door after the horse has bolted?
I think that's missing the forest for trees. The problem with these curl-to-bash approaches is not that you are literally unable to intercept and inspect them with enough effort and planning.
The problem is that:
1. The effort and care needed to test is unnecessarily high. You've got to guard against way more tricks from an interactive source that can see you and choose what it's going to deliver and how.
2. With no "standard" artifact that can be exactly compared, that work cannot be shared.
In contrast, release_1.2.3.zip isn't going to mutate under you and everybody can agree on what its size/hash/bytes ought to be, and if it deviates from that it sets off alarm-bells.
> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
Why would a convention often followed by good/careful actors bind what malicious/careless people create?
Well, if you're running software from someone you think can deliver malware to you (and not a middleman) then it's a lost cause anyways no? I don't see what the zip file adds. It's not like you're gonna be inspecting the code or binaries.
> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
Please take a look at this before making any assertions... https://github.com/omlahore/RemoveMacAI/blob/main/install.sh
Hey thats not the worst curlbash script i've seen
This isn’t really that much of an issue when we have tls tbh.
Like I get why it’s bad, but also homebrew package installation is a more organized version of this.
Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…
> If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.
They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.
this is awesome!!
Does apple not realize there is an SSD crisis happening? Used to love apple (Apple IIc was my first computer). But now? Terrible.
Another thing that bit me is that automatic updates reserve disk space even if no update is available. It makes sense when you have plenty of disk space but on my MacBook Air with 256gb of storage it was about 10% that I got back after turning off automatic updates. I’ll get a Mac with more storage next time so I don’t have to do that.
Oh, things are about to get worse with the new macOS "privacy/security" measures. They are going to curb agentic workflows even more. I don't know how Apple just finds new ways to annoy developers, but we're in a minority after all. Of 200 million Mac users, probably just up to 1 million are developers, and the rest are normies who can't tell when they should authorize or cancel the pop-up.
I'd argue that a lot of developers can't determine if an LLM generated command is actually safe or not.
It’s not about privacy, it’s about kneecapping competitors, just like when they blocked the advertising ID but exempted themselves from this because “Apple is not a third-party, we’re a second-party”.
Apple is an advertising company and thus inherently untrustworthy.
With LLMs, everyone's a developer now. Welcome to the mainstream.
Ah, if only that meant that there'll be less slop in the macOS code itself..
Apple hates developers
They love the ones that buy Apple hardware to develop apps for iDevices, pay the dev subscription and store fees for apps, or simply because they wanted a shiny UNIX and don't consider BSD/Linux OEMs worth their money.
Something horrible must have happened, if macOS users are curling shell scripts from the internet to make their desktops more like Linux.
curl|bash is now standard way to install packages on both macOS and Linux. It’s maddening, but it is now.
Meanwhile on Windows we mostly use the store or winget, funny times.
Yeah. I think of Windows as basically “homebrew comes preinstalled”.
The want some disk space back.
Personally, my limited experimentation with Apple AI has left me quite liking it.
The contents of the Exportable’Privacy Report’ are interesting to look through
Uncomfortable, but true.
GNOME has reached maturity and hasn't changed significantly in years, while Apple is busy destroying macOS.
Really? GNOME is not what I would recommend to people.
I should applaud their efforts, and I get that much of it is voluntary, but their bugs are numerous, notable and the way they interact with the rest of the universe (both people with accessibility needs, and the wider developer ecosystem on linux) can most accurately be described as arrogant and hostile.
KDE is the bastion of maturity here, and I would agree that it is mature.
I’m not sure how the love for GNOME continues when KDE (while not my personal choice) has clearly been running circles around it since GNOME3 and the gap has only widened since that change too.
Both desktops are pretty mature. I've run both of their Wayland stacks, and Mutter/KWin both perform great these days. It really comes down to personal preference for most use-cases.
I first saw it with Homebrew over a decade ago. It made it more linux, it's true. (Of course now that its for linuxes too, so they get to be more like macs.)
I see archive.today has the charming old ruby version on the bottom of a 2013 brew.sh page in 2013, when I must first have used it https://archive.ph/lCqJ1
But the form of incantation is now pervasive.Nope. The only people who notice or care about any of this are those who can't accommodate the storage. Outside that, it all just works better now (especially Siri).
Do people actually use Siri AI on the Mac? Whenever I need something done that needs AI on a mac I just use Claude Code.
I can imagine Siri AI being useful on iOS because of its deep integration to the OS. But for MacOS there’s better tools
People with 256GB laptops care when the 27 AI stuff burns up 10-20% of their storage.
So don't install Chrome.
Most people want Chrome for the inevitable site that doesn’t work in Safari.
The problem is Apple intelligence is decent, but not worth 20% of your storage decent.
Saying that Siri "works" is peak Apple fanboism.
Also "those who can't accommodate the storage" is funny.
What's that? You didn't pay Apple's 1200% markup on storage, just so you can have enough room for your actual work after the OS fills your disk with a bunch of bloat? What are you, poor?
The new one just works. Do try it.
It damn well better, for using 14gb+ of storage.
I'm sick of juggling disk space on my 1tb laptop AND I don't want an llm attack vector anywhere near my machine, this things getting nuked from orbit or i'm not updating to golden gate, ever.