Bad trend in the open-source community. Please don't ask your users to install stuff this way. Not that you can't be trusted, it leads to people dropping their guard.
Bad trend in the open-source community. Please don't ask your users to install stuff this way. Not that you can't be trusted, it leads to people dropping their guard.
Unequivocally, it is dangerous to run random pieces of code from the internet, it just seems odd to me that if this same code was in a nice packaged install wizard nobody would say anything about it.
jargonjargon [*&*@![]2\3
if [[jargon -f "words!"]]
jargon # jargon jargon
jargon /&$_)(82
fi # jargon the jargon
jar(){
gon # yay pictures! #
∑´∞§∞¶•ø¨ˆ∆£˜¡–ª¢ø•ª¶π™˜£º¥µ # <(^.^)> #
˚∆∂¥•¡º™ª•¶ƒ˙¨ˆ # #
˙π¡˜ø£•¶√≠˚•™µº–£¨≤ # <= ˚∆˚! but it works #
}
and just go to the next step.Projects like this are obviously targeted towards developers as they're hosted on github. If you really want to check out what the script is doing, just look at the file. Or better yet, clone the repo and use it/install however you want.
And what will be the right way to do it? The way people don't drop their guard? `./configure && make && sudo make install`? Or `sudo apt-get install`? How are any of these or many other options seemingly better than this?
edit: how about iOS? There have been news entries about them sending data where they shouldn't - that's a curated host. iOS is a lot more sandboxed, but that doesn't make the danger nonexistent.
Deleted comment
If you do, what's the difference?
When people are delivering software that isn't in the official repository, downloading a script and running it is no less secure than the alternatives.