|
|
|
|
|
by graypegg
143 days ago
|
|
Source? I would not trust this as-is. I do not like the `curl | sh` install strategy generally, but especially with something like this it feels sketchy. > We couldn't read your secrets even if we wanted to. Yes you can, you got to run a shell script with root privs when the cli was installed. You might only store ciphertext in your DB but skimming the shell script, it's dumping a mystery binary off your digitalocean spaces bucket and giving it all-user execute privs. There is no way to verify that binary isn't skimming my key. |
|
to be super candid, this isn’t open source because i don’t have the bandwidth to maintain/support another open source project. that may change as time goes on, though.
i get it’s a trade off, though, and i respect anyone not wanting to use it because of that.