So tell me. Do you think #curl should support plain SSH:// URLs to execute commands remotely?
@bagder Seems out of scope to me, but it's your project and I'd have already made a different decision with regards to AI-generated submissions.
@bagder It would be fair only if local execution `curl --exec example.com/install` would be supported as well.
@bagder heck no. security smell & pinata for hackers. curl attracts enough scrutiny by bad actors as it is
@bagder no, because I am a strong proponent of the UNIX principle. Curl does one thing great, let ssh do that other job.
can I also remind you all that curl already speaks SCP and SFTP, in command line tool and library...
@bagder my impression is that the main scope of cURL is to fetch remote files (and push files to remotes that supports it).
From that point of view:
- support the SCP and SFTP protocols makes totally sense
- support remote execution of arbitrary command would fall under scope creep (and open too mant new cans of worms) (and also increase attack surface by giving opportunity for new creative abuse of the feature)
@bagder Hm, ssh can already to it: https://malcontentcomics.com/systemsboy/2006/07/send-remote-commands-via-ssh.html why mis-use curl then for this?
@bagder IMHO no; we have ssh already for that.
@bagder throw in a TUI and vim bindings while you're at it /s
@bagder No, don't do it. We've got ssh for that.