Hacker News new | ask | show | jobs
by glad_it_worked 48 days ago
Installers should be long dead. We've had proper package managers for decades now (any Linux / BSD distribution, homebrew, etc.). Some call the infrastructure "marketplace", but that's still just a repo and a package manager.

The important part in my eyes are signed packages. Curl on a random website is too dangerous for my taste. Sure, a signature does not mean the software is not malicious. But it at least is a proof of that it comes from who it claims to come.

Curl on a random URL without signature check is a recipe for trouble.

1 comments

> Installers should be long dead.

Try to figure out how your package manager installs missing drivers - One of the things which Microsoft screwed up on Microsoft Store and MSIX packages. You literally can't touch PowerShell to install INF driver using PnP utility. You have to have executable installer.