5 ms·
You can do that with a direct link too: bash <(curl -s https://gitlab.com/grownetics/devops/raw/ef053050065c4928714edd94bedfc83a1225372a/tor_ssh.sh https://git
by bouk 8y ago
You can do that with a direct link too:
bash <(curl -s https://gitlab.com/grownetics/devops/raw/ef053050065c4928714edd94bedfc83a1225372a/tor_ssh.sh https://gitlab.com/grownetics/devops/raw/ef053050065c4928714...)
- v_lisivka 8y agoNo, you can't. Nothing will check SHA256 of a malware downloaded in this way, so nothing will stop malware from owning your host. To check, just put "127.0.0.1 gitlab.com" into your /etc/hosts and try to serve your own file from your URL. Git will detect this, curl will not.
- vegardx 8y agoYes, try it. Unless something has changed drastically curl still checks that certificates are valid.
- v_lisivka 8y agoIt looks like you assume that SSL guarantees correctness of the file. First, I had experience with substituted SSL certificates (by our government, at revolution), when errors were reported by Chrome only due to certificate pinning for Google services. Second, site can be hacked and replaced directly at the site.
- vegardx 8y agoWhen your threat level is government agencies then, sure, you have issues. But git wouldn't solve anything, unless you have a way to verify the hash or signature.