Remix.run Logo
▲ jacquesm 2 hours ago

Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.

▲nvme0n1p1 2 hours ago | parent | next [-]

The script, and the code the script downloads, both come from the same repo and were written by the same developer.

If you've already decided you trust the author, what's the actual threat here?

▲jacquesm 2 hours ago | parent [-]

I would not trust the author just like that.

But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.

▲user43928 2 hours ago | parent [-]

I think the point is that when a repo contains:

  program.bin
  install.sh
It seems rather pointless for me to thoroughly inspect the install script before I run the program.
▲halJordan 2 hours ago | parent | prev [-]

You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are

▲kbolino an hour ago | parent [-]

App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft).

▲Rohansi an hour ago | parent [-]

[dead]