4 ms·
Right, because a single git clone can't rm -rf your drive. A single "| sh", can, which is the point.
by jcapote 16y ago
Right, because a single git clone can't rm -rf your drive. A single "| sh", can, which is the point.
- tlrobinson 16y agoAnd what's the first thing people do after cloning a project they want to try out? Some might read all of the code, most will just run "./configure" or "make" or "rake" or "script/server" or whatever. All of which can execute arbitrary code. Piping a file to a shell isn't inherently less secure than downloading a zip or cloning a repo and blindly executing something from it. I'm willing to bet the majority of people who are complaining about the "curl URL | sh" trick also regularly download and execute code without verifying it won't own them.