logoalt Hacker News

IshKebablast Sunday at 1:21 PM1 replyview on HN

Downloading and installing a `.deb` or `.rpm` is going to be no more secure. They can run arbitrary scripts too.


Replies

ueckerlast Sunday at 1:28 PM

Downloading a deb via a package manager is more secure. Downloading a deb, comparing the hash (or at least noting down the hash) would also already be more secure.

But yes, that the run arbitrary scripts is also a known issue, but this is not the main point as most code you download will be run at some point (and ideally this needs sandboxing of applications to fix).

show 2 replies