logoalt Hacker News

mulmen • today at 4:39 PM • 2 replies • view on HN

It’s a shell script. You can download and read it before you run it. Piping it directly to the shell is reckless.

I’m not sure how your machine is configured but mine has permission boundaries and security policies that make sure programs are behaving properly. I don’t run everything with my personal user context.


Replies

bornfreddy • today at 5:53 PM

Actually... Server can detect if you are piping or not and serve a modified version for inspection.

But really, there is no reason not to use prebuilt packages for distribution. Curlpiping needs to die.

➕ show 2 replies
mynameisvlad • today at 5:46 PM

So then... Just do that and it's no longer reckless.

If someone wants to be reckless they can be. If someone doesn't, they also have that ability.