|
|
|
|
|
by Eeems
1730 days ago
|
|
I know I reacted hard to this statement: > Going further down the rabbit hole, the toltec GitHub page mentions that it works on top of the Entware distribution, and recommends what is basically “wget | bash”. I’m not a fan of this. Could I install my own rsync? We made sure that the toltec install process includes a hash of the install script to prove that it isn't modified by a man-in-the-middle. Toltec itself requires the use of SSL to connect after the fact, which lowers the risk after it's been installed. We are also exploring the implications of adding package signing[0]. 0. https://github.com/toltec-dev/build/issues/14 |
|
I apologize, I could have better expressed why I took the path I did. I'll edit the post later today.