3 ms·
This is why most packages are distributed with checksums, so you can be sure that what you're running is what the author intended.
by jcapote 16y ago
This is why most packages are distributed with checksums, so you can be sure that what you're running is what the author intended.
- rhymeswithcycle 16y ago... if you're getting the checksum from a trusted source that is separate from the package distribution server, or if the checksum is cryptographically signed. But I've never seen people get up in arms about someone publishing, say, a github link to some code that isn't accompanied by a checksum signed with a published PGP key you deem trustworthy.
- jcapote 16y agoRight, because a single git clone can't rm -rf your drive. A single "| sh", can, which is the point.
- tlrobinson 16y agoAnd what's the first thing people do after cloning a project they want to try out? Some might read all of the code, most will just run "./configure" or "make" or "rake" or "script/server" or whatever. All of which can execute arbitrary code. Piping a file to a shell isn't inherently less secure than downloading a zip or cloning a repo and blindly executing something from it. I'm willing to bet the majority of people who are complaining about the "curl URL | sh" trick also regularly download and execute code without verifying it won't own them.