5 ms·
Next thing you know they'll be running binaries without sending them through IDA Pro. (Which isn't to say that I disagree with the security concerns raised of
by trotsky 15y ago
Next thing you know they'll be running binaries without sending them through IDA Pro.
(Which isn't to say that I disagree with the security concerns raised of a curl|sh. Just that of course many people don't vet their various source code/shell scripts/executables. None the less, you should give them the opportunity to - a tarball and a detached signature seems to be a pretty friendly approach)
- deleted 15y ago[deleted]
- epistasis 15y agoOr even the laughable idea of downloading a tarball and running a configure script without first examining it for trojans. Such folly!
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- tlrobinson 15y agoMy problem isn't with the claim that this is an insecure method of installing software (it most certainly is), just that people are acting like it's an order of magnitude worse than what most people do regularly: download and execute software from unauthenticated/unencrypted websites. I would wager that many of the people complaining are guilty of that as well.
- deleted 15y ago[deleted]
- tlrobinson 15y agoSorry, my comment should have been a top level comment, not in response to yours. Not trying to pick a fight.