4 ms·
Would this be better if the pasted command included some checksum which was checked before piping into the `sh`? Can anyone who's better at bash than me give an
by joefreeman 11y ago
Would this be better if the pasted command included some checksum which was checked before piping into the `sh`? Can anyone who's better at bash than me give an example of how this could work in a relatively cross-platform way?
- nitrogen 11y agoYou would need to have a GPG signature with a well-known public key that is verified before executing the code.
- joefreeman 11y agoSorry, can you explain why? If the checksum is provided (as part of the sh snippet) by the website with the SSL certificate, isn't that enough reassurance?
- myhf 11y agoIf the snippet and the download are on the same site, then whoever controls that site at the moment can provide an accurate checksum of whatever malware they want to host. A signature is an improvement because it can give you some confidence that the current controller is the same as the original controller.
- itistoday2 11y ago> Would this be better if the pasted command included some checksum which was checked before piping into the `sh`? hashpipe does exactly that: https://github.com/jbenet/hashpipe https://github.com/jbenet/hashpipe