Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> No one should be running that without personally verifying each line.

Do you also verify each line of software you install? If you trust the author of certain software, why do you mistrust their install script?



It's not only the original author, don't forget, but it's any malicious actor that's managed to compromise that hosted script.

It should be viewed in the same way that a package author on NPM or PyPI may publish a malicious package, either themselves or via their account being compromised. It's not particularly common, but nor is it impossible and could present a good targe.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: