Hacker News new | ask | show | jobs
by _urga 2016 days ago
The malicious actor would simply edit the install script to comment out the checksum verification step, since they already own the script.
1 comments

Ah yes...good thing I don’t work in IT security...
No worries, I've made the same mistake and everyone in software security probably makes that mistake at some point.