Comment by Terr_

2 hours ago

I think that's missing the forest for trees. The problem with these curl-to-bash approaches is not that you are literally unable to intercept and inspect them with enough effort and planning.

The problem is that:

1. The effort and care needed to test is unnecessarily high. You've got to guard against way more tricks from an interactive source that can see you and choose what it's going to deliver and how.

2. With no "standard" artifact that can be exactly compared, that work cannot be shared.

In contrast, release_1.2.3.zip isn't going to mutate under you and everybody can agree on what its size/hash/bytes ought to be, and if it deviates from that it sets off alarm-bells.

> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

Why would a convention often followed by good/careful actors bind what malicious/careless people create?

Well, if you're running software from someone you think can deliver malware to you (and not a middleman) then it's a lost cause anyways no? I don't see what the zip file adds. It's not like you're gonna be inspecting the code or binaries.