3 ms·
Pardon my ignorance, but couldn't we just cryptographically sign bash scripts as well? Perhaps modify the installation script, something like `curl | some-veri
by aesyondu 6y ago
Pardon my ignorance, but couldn't we just cryptographically sign bash scripts as well?
Perhaps modify the installation script, something like `curl | some-verification-tool | bash`
- OskarS 6y agoNot easily, and probably not in a way that would work on all different systems (different distros/os's trust different keys).
- Arnavion 6y agoYou can. PowerShell already has a 15-year precedent of signed scripts - you generate a signature and embed it in the script in a specific way, and the shell can be configured to only run scripts if their signature is valid. (PowerShell script signing is based on standard Windows codesigning certificates, but of course this hypothetical bash script signature verifier can use GPG keys instead.)
- iso1631 6y agoThose who do not understand package managers are doomed to rewrite them. Badly.