7 ms·
whats the issue here? (genuine question) besides having to trust the author? and what installation methods do you recommend for cli tools?
by polityagent 7y ago
whats the issue here? (genuine question) besides having to trust the author? and what installation methods do you recommend for cli tools?
- parliament32 7y agoA package manager. https://www.seancassidy.me/dont-pipe-to-your-shell.html https://www.seancassidy.me/dont-pipe-to-your-shell.html https://sysdig.com/blog/friends-dont-let-friends-curl-bash/ https://sysdig.com/blog/friends-dont-let-friends-curl-bash/ https://news.ycombinator.com/item?id=12766049 https://news.ycombinator.com/item?id=12766049 Bonus points: serving a different script to people piping to bash, and those not: https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- polityagent 7y agolooks like the author also provides package manager installation on further reading of the readme. I'm still not quite seeing the issue with the curl to bash, I'm trusting the author by running their tool, regardless of the installation method. And I could always download the script first to check it right?
- polityagent 7y agoah I see, the greater risk of mitm attack due the script not being hosted by a package manager, fair enough.