I set up a quick demonstration to show risks of curl|bash and how a bad-actor could potentially hide a malicious script that appears safe.

It’s nothing new or groundbreaking, but I figure it never hurts to have another reminder.

  • quick_snail@feddit.nl
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    7 hours ago

    Anytime I see a project that had this in their install instructions, I don’t use that project.

    It shows how dumb the devs are

    • axx@slrpnk.net
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      Yes, this is the correct approach from a security perspective.