4 ms·
The owner of the website could sign responses, and you could verify them, in addition to TLS via HTTPS. I think that can make it at least as secure as package m
by ue_ 9y ago
The owner of the website could sign responses, and you could verify them, in addition to TLS via HTTPS. I think that can make it at least as secure as package management systems.
- saghm 9y agoYep, I agree. Providing checksums for scripts to curl isn't the the norm from what I've seen, though, which I think fits in with what GP (of my original comment) was saying. Also, I'm not super convinced that most users would bother verifying the checksum; from what I've seen, most people downloading Linux distro images don't even bother verifying the checksums that are provided.
- JeremyBanks 9y agoI'd be great if something like hashpipe could become standard on Linux for this purpose. See https://news.ycombinator.com/item?id=9318286 https://news.ycombinator.com/item?id=9318286
- saghm 9y agoThis is really cool! I hadn't heard of it before