4 ms·
> Or Download Literally immediately below the install script. I wish people would leave these low-effort comments on reddit where they belong.
by lowtolerance 8y ago
> Or Download
Literally immediately below the install script. I wish people would leave these low-effort comments on reddit where they belong.
- erikb 8y agoAnd? Just because "smoking creates cancer" stickers on cigarettes they don't kill people anymore? Just having that suggestion burried somewhere on page 300 of a documentation is worth enough to mention it. It's not a question of free choice but a question of how we educate people to develop software.
- lowtolerance 8y agoI thinks it’s a matter of how we educate our arm-chair security experts, actually. What is the difference between blindly trusting a script piped directly from the source and blindly trusting a script packaged in a tarball? Can you honestly say that you’ve audited every piece of code that you execute on your system, and can say with complete confidence that no data on your system has been tampered with? Do you reverse engineer and audit your unsigned binary installers before executing them? If not, then I’m very curious to hear why you believe that you are somehow avoiding the same risks posed by a curl | sh script such as this one.