Hacker News new | past | comments | ask | show | jobs | submit login

That is better to me than installing a random binary. You can trivially audit the curl. Also, the curl > bash thing usually comes from the project maintainer (as in the case of Bun) vs some rando flatpacker.



Not if the bash part then turns around and installs a random binary, which is often the case. How do you know how thoroughly it's been audited by third parties? Does it have a security patch mechanism built into it?


In all fairness, Jia was indeed the co-maintainer of the project. He modified SECURITY.md as well[1].

[1] https://github.com/tukaani-project/xz/commit/780d2c236de0e47...


No, you cannot audit the curl at all. What a website serves you now is not neccessarily what the website serves you one minute from now.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: