logoalt Hacker News

jacquesm • yesterday at 8:52 PM • 2 replies • view on HN

Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.


Replies

nvme0n1p1 • yesterday at 9:12 PM

The script, and the code the script downloads, both come from the same repo and were written by the same developer.

If you've already decided you trust the author, what's the actual threat here?

➕ show 1 reply
halJordan • yesterday at 9:18 PM

You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are

➕ show 1 reply