Comment on Introducing Pow, a zero-configuration Rack server for Mac OS XparentComments−sstephenson15yJust as anyone who can spoof DNS entries could swap some other theoretical Pow installer with a malicious one.I'm not seeing how Pow's installation process is any less secure than, say, downloading a disk image from a random site.−michaelfairley15yNot if it's served over SSL.−tesseract15yThat has nothing to do with whether the installer is a shell script or a binary.−wlllOP15yThis comment is a repeat, but that may not necessarily be true:http://www.imperialviolet.org/2011/03/18/revocation.html
Comments
Just as anyone who can spoof DNS entries could swap some other theoretical Pow installer with a malicious one.
I'm not seeing how Pow's installation process is any less secure than, say, downloading a disk image from a random site.
Not if it's served over SSL.
That has nothing to do with whether the installer is a shell script or a binary.
This comment is a repeat, but that may not necessarily be true:
http://www.imperialviolet.org/2011/03/18/revocation.html