| 
			
			 | 
		#1 | 
| 
			
			
			
			 Junior Member 
			
			![]() Posts: 4 
				Karma: 10 
				Join Date: May 2020 
				
				
				
				Device: cross-platform 
				
				
				 | 
	
	
	
		
		
			
			 
				
				scary installation method for linux
			 
			
			
			First, let me say I am so grateful for Calibre! Thank you all for your work developing and supporting it. 
		
	
		
		
		
		
		
		
		
		
		
		
	
	I came to the forum because the installation method for linux makes me really nervous, and I can't imagine I'm the only one. Copy and paste a terminal command that downloads a bash script off the web and runs it sudo?! Um ... I'm no security expert, and maybe I'm naive to think AppImage or package managers are somehow more secure, but that just does not sound like a generally good policy. Is there any talk of getting it into Ubuntu repos or anything like that? Thanks in advance for thoughts.  | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#2 | 
| 
			
			
			
			 creator of calibre 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,609 
				Karma: 28549044 
				Join Date: Oct 2006 
				Location: Mumbai, India 
				
				
				Device: Various 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			calibre is available in all repos but use the official binaries if you want support. A distribution version of any software is almost always strictly worse than the official version, since its the ofifcial version plus random patches added by people of lets say, very varying competence.  
		
	
		
		
		
		
		
		
		
		
		
		
	
	There is nothing scary about running bash scripts from the internet. And you dont need to run it under sudo if you dont want to, it supports an isolated mode as well. And just for the record, the installer is a python script, not a bash script, its just wrapped in a bash script to find the right python binary to run the actual installer with.  | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#3 | 
| 
			
			
			
			 Weirdo 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 934 
				Karma: 11941602 
				Join Date: Nov 2019 
				Location: Wuppertal, Germany 
				
				
				Device: Kobo Sage, Kobo Libra 2, Kindle Paperwhite 2021, Kindle Scribe 2022 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			For what it's worth, there's a flatpak available on flathub. It's always trailing behind for a few days. If that's acceptable to you, here's the link: 
		
	
		
		
		
		
		
		
		
		
		
		
	
	https://flathub.org/de/apps/com.calibre_ebook.calibre  | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#4 | 
| 
			
			
			
			 Still reading 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 15,004 
				Karma: 111111255 
				Join Date: Jun 2017 
				Location: Ireland 
				
				
				Device: All 4 Kinds: epub eink, Kindle, android eink, NxtPaper 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			Flatpack is more problems than the script from Kovodgoyal 
		
	
		
		
		
		
		
		
		
		
		
		
		
			If you don't trust his script, why trust Calibre? If you trust Calibre, then trust the script. Same person. Flatpacks also update without asking for a password/sudo. I've replaced all but one now with either proper deb packages or direct installs. A flatpack is extra complexity, a 3rd party and less secure updating. There is nothing more scary about the terminal script than a obfuscated GUI install. Steam, Viber (by Rakuten than owns Kobo) and Brother's print/scanner drivers all offer terminal scripts for install. So does WINE, Thunderbird, Waterfox etc. It's not inherently less secure or scary than downloading a Windows msi file to desktop and double clicking. For decades the only way to install was in a console. Last edited by Quoth; 11-17-2023 at 06:09 AM.  | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#5 | 
| 
			
			
			
			 Well trained by Cats 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 31,267 
				Karma: 61916422 
				Join Date: Aug 2009 
				Location: The Central Coast of California 
				
				
				Device: Kobo Libra2,Kobo Aura2v1, K4NT(Fixed: New Bat.), Galaxy Tab A 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			But only use the official script on the download page. There are MILLIONS OF CALIBRE USERS.  https://calibre-ebook.com/dynamic/calibre-usage in the last 60 days. I think if there was scary, we would hear . 
		
	
		
		
		
		
		
		
		
		
		
		
	
	If you are worried about issues, check here (MR) before updating.  | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#6 | |
| 
			
			
			
			 Resident Curmudgeon 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 80,782 
				Karma: 150249619 
				Join Date: Nov 2006 
				Location: Roslindale, Massachusetts 
				
				
				Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3 
				
				
				 | 
	
	
	
		
		
		
		
		 Quote: 
	
  | 
|
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#7 | 
| 
			
			
			
			 Custom User Title 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 11,359 
				Karma: 79528341 
				Join Date: Oct 2018 
				Location: Canada 
				
				
				Device: Kobo Libra H2O, formerly Aura HD 
				
				
				 | 
	
	|
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#8 | |
| 
			
			
			
			 Bibliophagist 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 48,175 
				Karma: 174315444 
				Join Date: Jul 2010 
				Location: Vancouver 
				
				
				Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos 
				
				
				 | 
	
	
	
		
		
		
		
		 Quote: 
	
 And, David, stop responding to the troll. Last edited by DNSB; 11-17-2023 at 09:10 PM. Reason: Added advice to meself!  | 
|
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#9 | 
| 
			
			
			
			 null operator (he/him) 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 22,018 
				Karma: 30277294 
				Join Date: Mar 2012 
				Location: Sydney Australia 
				
				
				Device: none 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			The number of Linux users with calibre related problems is disproportionate to their number by a country mile… ditto the other four multi-platform products I use.
		 
		
	
		
		
		
		
		
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#10 | 
| 
			
			
			
			 Bibliophagist 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 48,175 
				Karma: 174315444 
				Join Date: Jul 2010 
				Location: Vancouver 
				
				
				Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			Anyone in possession of a moiety of their mind will admit quite a few programs have more issues on Linux proportionate to the number of users than the same programs on MacOS or Windows when using the GUI. This does not lead me to conclude that Windows or MacOS never have issues. Anyone who has participated in any of the Windows Beta or Preview programs knows that all too well.
		 
		
	
		
		
		
		
		
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#11 | 
| 
			
			
			
			 Junior Member 
			
			![]() Posts: 4 
				Karma: 10 
				Join Date: May 2020 
				
				
				
				Device: cross-platform 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			I sure didn't mean to start a Windows-Linux fight. 
		
	
		
		
		
		
		
		
		
		
		
		
	
	I am grateful for the thoughts. I mean, I am of course consoled by the fact that it is both open-source and widely-used, and that if I were a better coder I could check the script myself. (FWIW, I asked Claude's AI to look it over and, with many a disclaimer, it said there thatwere no security red flags.) I guess I'm just paranoid enough to wonder - not specifically about kovidgoyal, mind you, but about anyone in such a position - whether they might not be tempted someday to abuse such trust once it's been built, to turn a handsome profit with ransomware or whatever. Meanwhile I'll back up and/or encrypt my stuff as securely as I can, and then trust-but-verify. Thanks again, sincerely, by the amazing app - in general this kind of open-source software just restores my faith in humanity, despite the appearance of deep skepticism here.  | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#12 | |
| 
			
			
			
			 Well trained by Cats 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 31,267 
				Karma: 61916422 
				Join Date: Aug 2009 
				Location: The Central Coast of California 
				
				
				Device: Kobo Libra2,Kobo Aura2v1, K4NT(Fixed: New Bat.), Galaxy Tab A 
				
				
				 | 
	
	
	
		
		
		
		
		 Quote: 
	
 The ransomware folk go after Windows users because there are so many, that even a 1% return on (code and deploy) effort is HUGE.  | 
|
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#13 | 
| 
			
			
			
			 Wizard 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,075 
				Karma: 12500000 
				Join Date: Aug 2013 
				Location: Okanagan 
				
				
				Device: Sony PRS-650, Kobo Clara 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			I'm using the Calibre that comes with my distribution (MX, based on Debian.) I guess I got lucky and avoided all those incompetent developers.-) I have used the official binaries in the past, also without problems. spetey, if you use the packages in your distro comfortably, you can use Kovid's binaries equally comfortably.
		 
		
	
		
		
		
		
		
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#14 | |
| 
			
			
			
			 Resident Curmudgeon 
			
			![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 80,782 
				Karma: 150249619 
				Join Date: Nov 2006 
				Location: Roslindale, Massachusetts 
				
				
				Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3 
				
				
				 | 
	
	
	
		
		
		
		
		 Quote: 
	
  | 
|
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
| 
			
			 | 
		#15 | 
| 
			
			
			
			 Member 
			
			![]() Posts: 21 
				Karma: 10 
				Join Date: Nov 2022 
				
				
				
				Device: PW5 
				
				
				 | 
	
	
	
		
		
		
		
		 
			
			> Copy and paste a terminal command that downloads a bash script off the web and runs it sudo?! Um ...  
		
	
		
		
		
		
		
		
		
		
		
		
	
	Well, I guess that's a good point. I didn't know what I was doing and took that risk since the repos were out of date and flathub was problematic. Hope that doesn't get hacked or anything. Or pressured to put a back door on your machine. Maybe run it in a vm?  | 
| 
		 | 
	
	
	
		
		
		
		
			 
		
		
		
		
		
		
		
			
		
		
		
	 | 
![]()  | 
            
        
            
| Tags | 
| installation, linux | 
            
  | 
    
			 
			Similar Threads
		 | 
	||||
| Thread | Thread Starter | Forum | Replies | Last Post | 
| Calibre installation on linux | us185damiani | Calibre | 1 | 01-13-2021 12:46 PM | 
| Calibre 2.0, Linux, Chinese input method | anavin | Calibre | 1 | 08-23-2014 03:19 AM | 
| Stupid Linux installation problem | Saioko | Calibre | 3 | 04-30-2013 03:25 PM | 
| Installation for Linux - Why so hard? | Wentworth | Calibre | 9 | 08-15-2011 11:39 AM | 
| Planned installation method? | Manichean | OpenInkpot | 4 | 07-26-2008 06:03 AM |