Hacker News new | ask | show | jobs
by folmar 2066 days ago
A reasonable attacker would provide different file to curl and to the browser so you inspect something else then you run and don't even have a copy of the file.