logoalt Hacker News

account42last Wednesday at 1:54 PM2 repliesview on HN

> curl -sSL https://install.example-cli.dev | bash # safe

This is not and has never been safe.


Replies

digitalsushilast Wednesday at 2:00 PM

It's about as safe as trusting all the add-ons in your IDE, and all the packages your node app pulls from random package repos.

It's just the plausible blame that shifts.

If you read the script before you pipe it into your shell, it's safe.

And if that's not safe, then it's just as dangerous to trust that an unopened bottle of ketchup is safe.

Nothing is safe. Everything is a judgement. Being culpable is a professional service. Lucky people out-earn unlucky people. The world is a scary place.

show 7 replies
tetris11last Wednesday at 5:35 PM

it really irks me that this is the default way to install micromamba

https://mamba.readthedocs.io/en/latest/installation/micromam...