| > So your claim that binary software is untrustable falls short in the practical world. Where the hell do you think I made that claim? > So file an issue. Are you just trying to ignore everything I say? I responded to a claim that shell installers would be written correctly, with evidence that a fairly sizeable company doesn't get it right. Your response to that is that it doesn't matter. > You think it's more likely they will notice the missing 's' in the click-to-download-the-installer scenario than in the paste-a-command-into-the-shell scenario? I find that hard to believe. A giant green bar is a little bit more than a single letter. --- You really don't seem interested in a conversation about the shortcomings that exist. You seem interested only picking holes and saying that you are correct. I have no interest in responding to that kind of conversation. |
Right here:
https://news.ycombinator.com/item?id=16144785
You said:
"Don't install random binaries either. The security implications of that should be fairly obvious."
> a fairly sizeable company doesn't get it right.
Fairly sizable companies mess up a lot of things. That still isn't a good argument against piping to shell though, since it isn't exclusive to that method.
> A giant green bar is a little bit more than a single letter.
Ah but you don't get the green bar for the file you are downloading, you only get it for the page that linked to it. So that's not good enough either.
> You really don't seem interested in a conversation about the shortcomings that exist.
You aren't raising many valid ones; it isn't my fault that the holes are so easy to find.
If you ease up on the hostile language and come back with some arguments that are a bit stronger, maybe you won't feel like this conversation is so one-sided.
I am truly interested in some serious arguments against piping to shell, if there are any besides the one I raised, since all I hear are these bogus ones any time this topic comes up. I have no horse in the race, but cargo cult shunning of a popular install method isn't right. One ought to have real arguments which stand up to a little scrutiny.