| > Just because you have a URL, doesn't mean it is connecting to the expected IP. Ignoring how weak of an argument that is, I don't see how that is any different of a risk between curl-pipe-to-sh and regular software downloads. > Remember who these kinds of installs target: developers with little experience. I think that's a little condescending. I image these kinds of installers target folks who want to get up and running quickly and conveniently, regardless of their experience. And I imagine, on average, folks pasting this into their shell have more than average experience already, since they (1) went out of their way to try this software and (2) know how to open a shell and copy commands into it. > You can't ensure they'll notice a missing 's'. You can't ensure a worn-out admin will either. You think it's more likely they will notice the missing 's' in the click-to-download-the-installer scenario than in the paste-a-command-into-the-shell scenario? I find that hard to believe. > Have a glance over Heroku's Ubuntu script.[0] It's not fenced, if that echo breaks, it could case some chaos. So file an issue. If their normal installer has bugs in it, things would break too. I don't see the difference. Buggy installers are buggy, which is just an argument against buggy installers, not against different install methods. > I wouldn't curl a microcode update. You missed the point. You can download it any way you like; unless you have its source, though, you can't audit it at all. So your claim that binary software is untrustable falls short in the practical world. |
Where the hell do you think I made that claim?
> So file an issue.
Are you just trying to ignore everything I say? I responded to a claim that shell installers would be written correctly, with evidence that a fairly sizeable company doesn't get it right.
Your response to that is that it doesn't matter.
> You think it's more likely they will notice the missing 's' in the click-to-download-the-installer scenario than in the paste-a-command-into-the-shell scenario? I find that hard to believe.
A giant green bar is a little bit more than a single letter.
---
You really don't seem interested in a conversation about the shortcomings that exist. You seem interested only picking holes and saying that you are correct.
I have no interest in responding to that kind of conversation.