← Back to context

Comment by sergiotapia

1 day ago

You're right it's much safer to click next > next > next > next > finish.

A big difference between the safety of "next > next > next > finish" and "curl | bash" is one of them is dynamically loaded from an external source that could change between runs, and the other can be fully downloaded and vetted in a single check, and then once it's safe, it's probably safe 10 years from now.

  • Every download of a piece of software could be unique.

    • Which is why we have sha1, md5 and sha256 hashes on display, so you can validate with a very high level of certainty, especially for sha256 at least for now, that the file is the same one.

      We have existing paradigms for this.

      Additionally, installers are signed with certificates on Windows.

      All of these are strictly more trustworthy than curl | bashing.

      1 reply →

Yeah installation has always been such a security issue. So many programs are just random links that download a file. You have to trust that the host has not been compromised all packages that were used to build it were not compromised etc.

With ai models getting better we may be able to do analysis on the actual underlying bytes of the files we download to properly scan them for malicious code patterns and build systems which sandbox programs and watch inbound and outbound traffic/ system level actions from them and flag suspicious requests for further analysis by smarter models.

REA shows that ai are very good at understanding low level code and reverse engineering it so this could potentially be applied to application level security aswell.