Hacker News new | ask | show | jobs
by arcticfox 3531 days ago
Sure, but how is that any less secure than other installation alternatives? As the site owner, I could swap out a valid package for a troll package at any moment to any subset of users I wanted to if they're not validating the contents of it...
1 comments

You can't change the contents on a user's local storage that they've verified.

Curlbash lets you change out offerings at will, and leaves no auditable source for the user.