3 ms·
I know this is considered a bad practice - but how is it worse than downloading it first and then running it? It's only better if someone is going to inspect th
by statictype 5y ago
I know this is considered a bad practice - but how is it worse than downloading it first and then running it? It's only better if someone is going to inspect the script before running it and how many people actually do that? Or will do it if they were forced to?
- jeroenhd 5y agoOptimally, you want to download software from a static, external source that people can vet, preferably protected from tampering with digital signatures. For most of these scripts, there's no way to know if the file you'll receive will be the same as a file someone with an interest in installer security will receive. You'd have to download from a source that you can believe to be reasonably static to get the minimum amount of trust at the least. It's trivial to serve different files to different user agents, and with terminal escape codes you could even hide malicious code from the few people that cat these scripts. I don't like downloading files from a project's own, potentially dynamic, server, and executing them directly, even though that's commonly the only way to run certain tools. In my opinion, downloading github release files or even just the scripts from github directly is worse than using reliable repositories with signatures and all that, but better than downloading random shell or exe files and executing them as admin. You'll always be at some kind of risk of software manipulation, so you have to choose how much risk you want to accept when it comes to this stuff.
- AstralStorm 5y agoTechnically GitHub releases can be signed, but even then you're trusting the release build bot most of the time...