3 ms·
I thinks it’s a matter of how we educate our arm-chair security experts, actually. What is the difference between blindly trusting a script piped directly from
by lowtolerance 8y ago
I thinks it’s a matter of how we educate our arm-chair security experts, actually.
What is the difference between blindly trusting a script piped directly from the source and blindly trusting a script packaged in a tarball? Can you honestly say that you’ve audited every piece of code that you execute on your system, and can say with complete confidence that no data on your system has been tampered with? Do you reverse engineer and audit your unsigned binary installers before executing them? If not, then I’m very curious to hear why you believe that you are somehow avoiding the same risks posed by a curl | sh script such as this one.