3 ms·
What's unsafe about this? You download a tarball, extract it, run an installer, and then you can run the program. If the archive get corrupted on the way, unxz
by wmt 11y ago
What's unsafe about this? You download a tarball, extract it, run an installer, and then you can run the program. If the archive get corrupted on the way, unxz will complain.
If it's about running programs from the internet you haven't code reviewed, then you could just review the sources and the installer before running install.sh?
- wtallis 11y agoIs xz compression designed to be as tamper-resistant as encrypted data?
- astrobe_ 11y agoIf you're going paranoid mode, do it properly. GP pointed out that you're about to run a program from an unknown. That's a bigger issue than some devil doing MITM or whatnot.
- mikeash 11y agoThe track record of open source projects being non-malicious is decent, especially if you have a bunch of other people looking at the project, you briefly consider the author's reputation, etc. The track record of random unknown MITMers being non-malicious is much less decent. You vastly increase your attack surface if you download and execute code over HTTP.