3 ms·
... if you're getting the checksum from a trusted source that is separate from the package distribution server, or if the checksum is cryptographically signed.
by rhymeswithcycle 16y ago
... if you're getting the checksum from a trusted source that is separate from the package distribution server, or if the checksum is cryptographically signed.
But I've never seen people get up in arms about someone publishing, say, a github link to some code that isn't accompanied by a checksum signed with a published PGP key you deem trustworthy.
- jcapote 16y agoRight, because a single git clone can't rm -rf your drive. A single "| sh", can, which is the point.
- tlrobinson 16y agoAnd what's the first thing people do after cloning a project they want to try out? Some might read all of the code, most will just run "./configure" or "make" or "rake" or "script/server" or whatever. All of which can execute arbitrary code. Piping a file to a shell isn't inherently less secure than downloading a zip or cloning a repo and blindly executing something from it. I'm willing to bet the majority of people who are complaining about the "curl URL | sh" trick also regularly download and execute code without verifying it won't own them.