Comment by jacquesm
2 hours ago
Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
2 hours ago
Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
The script, and the code the script downloads, both come from the same repo and were written by the same developer.
If you've already decided you trust the author, what's the actual threat here?
I would not trust the author just like that.
But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.
I think the point is that when a repo contains:
It seems rather pointless for me to thoroughly inspect the install script before I run the program.
You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are
App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft).
[dead]