3 ms·
I see, and this was your original point. I guess the only threat there (that I can see) is that the install script can be malicious, but your point was that yo
by merlinsbrain 9y ago
I see, and this was your original point.
I guess the only threat there (that I can see) is that the install script can be malicious, but your point was that you’re trusting the owners of the website anyway by downloading their binary and executing their code locally.
It can be argued that it’s probably easier to ship malicious code outside the main repository (e.g. in an install script) but I do not have a good counter besides this weak argument.
The checksum is indeed usually on the same page and does make it useless in my hypothetical MITM.