function install_my_software() {
...
}
install_my_software()
If the script is partially downloaded, it won't have any effect.It just seems to me that the main should worry about interfacing with the outside world, and the rest of your code should really just be written as a library.
I made a utility "shacat", which takes a sha1 checksum as an argument and then pipes input to output iff the sum of input matches the sum
e.g.
$ curl http://site.com/script | shacat 7ef39183 | sh
You don't even need https! You copy the command from the site including the sha sum, so it can't have been tampered withOf course, getting people to use shacat is the hard part
Why that? Have we never heard of defaced web pages?
Granted, using shacat is much better than piping into sh. But basic learning from security breaches is that nothing is safe, you only can find ways to do thing in a less catastrophic manner than others.
Well if you can't trust the website you're screwed anyway. If the website is compromised then absolutely any way they have of installing software is broken