5 ms·
> If you attempt to read the script in your browser first, and everything's great, then go pipe to bash, the server can send alternate content based on your use
by chrismonsanto 10y ago
> If you attempt to read the script in your browser first, and everything's great, then go pipe to bash, the server can send alternate content based on your user agent.
If you can't trust the site to give you a safe installer then you can't trust the rest of the sources it gives you either--you would need to audit the entire package. Virtually nobody is going to do that. Singling out the installer as uniquely dangerous is security theater.
- seanp2k2 10y agoWindows and OSX also do this and present pointless non-defeatable "omg but this is from the scary internet, are you SURE you want to run it????"
- thedudemabry 10y agoTo be fair, those have been very effective in keeping my non-techie family members from accidentally installing malware because they'll at least check with me when presented with a scary system dialog. And it hasn't impacted my own use other than the occasional extra clicks. In a locked-down corporate setting, I can see how that could be maddening, though.
- inimino 10y agoThat's for the benefit of people who don't really realize that installing software from the internet is dangerous (i.e. most users). This discussion is about safe methods once you have decided to install something from the internet, which is different.