This same old boring, worn out comment? Let's just skip to the end, shall we?
A: omg you're piping curl to bash! so insecure!!
B: well wait a second, i) you can just curl the script & inspect it before running it if you want ii) step-by-step install instructions still require that you trust the source of the code and iii) how is installing a precompiled binary any more secure? All scenarios short of personally auditing the source code require you to trust someone.
A: Hmm ok well I guess so.
~the end~ This is how this conversation has gone down the last 5 times I saw it. Can we please discuss the tool itself now?
I was going for ease of use and encryption. This install procedure is not secure and people should review the source, but the more steps there are the less likely people are to use some type of encryption.
I would like to use a package management tool in the future.
Comments
End to end encryption, focus on security. Install is done by piping a script you wget to bash.
This same old boring, worn out comment? Let's just skip to the end, shall we?
A: omg you're piping curl to bash! so insecure!!
B: well wait a second, i) you can just curl the script & inspect it before running it if you want ii) step-by-step install instructions still require that you trust the source of the code and iii) how is installing a precompiled binary any more secure? All scenarios short of personally auditing the source code require you to trust someone.
A: Hmm ok well I guess so.
~the end~ This is how this conversation has gone down the last 5 times I saw it. Can we please discuss the tool itself now?
I was going for ease of use and encryption. This install procedure is not secure and people should review the source, but the more steps there are the less likely people are to use some type of encryption.
I would like to use a package management tool in the future.