sh | wget http://www...something.com/install.sh
to install something automatically! Way too many projects do it, from my head: rvm and oh-my-zsh.
sh | wget http://www...something.com/install.sh
to install something automatically! Way too many projects do it, from my head: rvm and oh-my-zsh.
If you download the code manually, how are you to know that the server sent you the exact same code? They could be checking HTTP headers for a bootloader device, or might only be infecting 1 in 100 downloads. You'd never spot it.
In theory, yes, `curl | sh` is the same as configure&make is the same as downloading your initial iso image and installing the system from it. In practice they have different risks associated with them.
What about `cd /usr/ports/www/firefox && make clean install`?
For nefarious purposes I actually think it's worse than the much-maligned "curl|sh" scenario. I bet a reasonable number of people will end up trying to download the script, out of curiosity if nothing else. If it's doing anything not straightforward, it would get attention. In contrast, who would notice a line added to the middle of a 8000 line auto-generated configure script?
The point is, technically there isn't anything different between `curl | sh` and installing a system from either a downloaded .iso or a mailed DVD. Both run code from untrusted sources on your computer. But in practice they're very different because of user behaviour and ability to validate data before running. There's a whole spectrum in between and configure&make is somewhere on it.
Of course, you have to start trusting at some point. But with HTTP, you have to also trust the wifi AP, its owner, all of the routers between you and the server, DNS... At least https takes a lot of those (but not all) out of the equation, while GPG goes even further.