Show HN: "curl … | sh" is bad.
poww.cx
poww.cx
(edit: Oh. You're doing user-agent sniffing for curl. Fair enough, but this still isn't any less secure than downloading and executing a binary.)
A good example of the fake downloads can be found with people running ads for VLC that link to their malware/adware invested versions (presumably, I've never actually bothered to investigate them).
But I've never seen people get up in arms about someone publishing, say, a github link to some code that isn't accompanied by a checksum signed with a published PGP key you deem trustworthy.
Piping a file to a shell isn't inherently less secure than downloading a zip or cloning a repo and blindly executing something from it.
I'm willing to bet the majority of people who are complaining about the "curl URL | sh" trick also regularly download and execute code without verifying it won't own them.
if people catch on to that and start checking with curl first, you could even serve the friendly content the first time someone fetches it with curl.
It's not.
Yes, the user-agent sniffing is clever, but it's circumventing a security precaution that isn't even possible with a binary installer.
More discussion here: http://news.ycombinator.com/item?id=2420648
It's harmless to run.
And if the download and webpage are hosted on the same machine (like, practically always) the checksum won't help you either.
If you want to run third-party stuff and not willing to look at every little assembly instruction at one point you're going to have to trust somebody.
Of course this can just be Apple (app store) or the Debian/insert-distro-here guys (only run code that's from apt packages from the official repositories).
I'll just take the occasional risk.
Executing a `rm -rf /` is not hard to do, and you wouldn't even see that text in a program. Basically you're depending on the statistical probability that if there is a hack, someone else will get hit before you and it can be identified and resolved before everyone is affected. Someone has to take one for the herd.