3 ms·
How is this different than say, brew install <whatever>? I'm trusting someone to serve me a piece of code to run either way. Brew, or the people that provide t
by phn 10y ago
How is this different than say, brew install <whatever>?
I'm trusting someone to serve me a piece of code to run either way. Brew, or the people that provide the https cert for the given endpoint, right?
- htns 10y agoWhen a third party is involved there is a degree of accountability. A proper package repository would require everything to be logged and signed.
- phn 10y agoWell, there's also accountability if I'm installing, say, docker. Surely they want to make it easy to install their thing without a hitch, and that's why they provide https://get.docker.com https://get.docker.com for me to pipe into bash. My point is it all boils down in who you trust. If you are downloading something unknown, sure, it's harder to go wrong with a package manager (if the package is available), but you're still trusting someone not to attack you or to leak the private keys. Crucifying curling into bash has nothing to do with how safe you are. It's almost like saying "Never run anything you download from the internet, it's dangerous!"