3 ms·
So it is safer to use `sh -c "$(curl https://whatever.com/install.sh https://whatever.com/install.sh)"`?
by maple3142 6y ago
So it is safer to use `sh -c "$(curl https://whatever.com/install.sh https://whatever.com/install.sh)"`?
- tobyhinloopen 6y agoNo. It’s safer to download the file, inspect it manually, and then run it.
- hvdijk 6y agoOnly mildly so. This hides from the server the fact that you are not checking what is received, so prevents the server from adapting its results based on that, but still allows a server to just unconditionally serve a malicious script. The safe way is to save to a file, actually inspect the file to make sure there is nothing malicious in there, then run that file.