Exactly. Similar questions
Why does a user need to download a file to achieve the goals? Does doing so provide added utility?
Does obscurification provide some benefit?
Does distribution in this manner help normalize environments which scammers take advantage of?
I'd argue:
- Don't make users download things they don't have to.
- Serving in plain text gives higher utility as users can view it on any device (e.g. mobile. Am I the only one that reads repos on mobile?)
- A GitHub alternative also provides the capacity to download an archived zip, thus achieving any benefits that aren't obscurification related
- Git helps for better archiving as we can have a track record of commits and changes (this is labeled "Part 1"!)
- Did no one else notice that there are ".github" directories with workflows? But there is no ".git" folder? I'd honestly like that...
- While a zip itself is not an executable and not generally dangerous in of itself, scammers (hackers) do take advantage of such environments. Because you can... change a file extension. Or because a user may double click the zip to extract, but this will cause execution. Or idk, hackers are fucking smart and people are dumb.
I'm a bit peeved that people feel the need to explain to me that a zip isn't nefarious in of itself, because that's not what I was concerned with (and that there's several such comments and we don't need to keep repeating the same comment...). My concern is with how such formatting is (as best as I can tell) not necessary, suboptimal, and normalizes practices that nefarious actors take advantage of. This topic is obviously hot, so I won't be surprised if there are "alternative links" that could just contain straight up maleware. Yeah, the user has to execute it, but people are dumb, lazy, and/or tired and there is a *
better* form of distribution that just doesn't leave this script-kiddy style attack around. Like for fuck's sake, people at intelligence agencies plug in USBs they find on the ground...