Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure, but you can review the git repo's content/commits in plain text, while curl-pipe-bash would require you to reverse engineer the binary that's downloaded.

If somebody hacks the project's home page and switches the download location to a hacked binary, you'd be none the wiser. Of course, somebody could hack the repo and add a deliberate vulnerability as well, but at least you would have a trail of it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: