Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

piping to bash as an install method?

didn't we decide this was a really really bad idea?



It could definitely be dangerous, but nothing is stopping you from inspecting the script before you run it.


Not saying you are wrong (you are not, you technically can download the script in one step, read it and then feed the local copy to bash) but someone posted a proof of concept a couple months ago that used user agent sniffing to potentially fool people into reading one thing and running another if they used the browser to read the source but curl to pipe the script into bash.


I wasn't aware of that, thanks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: