>Note: if you get an error you might need to change the execution policy (i.e. enable Powershell) with set-executionpolicy unrestricted -s cu
The Windows equivalent of curl | sudo bash...
Please don't do this. Sign your Powershell scripts.
>Note: if you get an error you might need to change the execution policy (i.e. enable Powershell) with set-executionpolicy unrestricted -s cu
The Windows equivalent of curl | sudo bash...
Please don't do this. Sign your Powershell scripts.
Note you don't need to run as admin to install scoop--it's all about installing stuff for your user account without requiring elevation.
You are right though that you probably shouldn't just run scripts like this if you don't trust them. I do it all the time because it's convenient and I'm not running elevated. You can always check the source if you're not sure.
The iex [remote-script] probably will run in that case actually, just not the 'scoop' command. Which shows what a farce the PS execution policy is.
I presume you haven't been in an organisation where all the hot new things come in and screw things up with this kind of thinking?
In general you just get that lot trained when the next wave are incoming...
I assume no one is old enough or so far away from reality that they don't remember the hell that was VBA and macros in the late 90's and early 00's?
They're very sensible organisations IMHO.
Theyre not oppressive and to be shunned. They just take data protection seriously.
Scoop is aimed pretty squarely at HN readers, not so much at people that are ok with working at an organisation that doesn't trust them to run programs on their computer.
We trust people to run programs on their computer, just not ones that download other programs and ones that have dubious signing or security policies.
The prevailing attitude amongst startups and even big businesses of blasting everything carelessly with shotguns because it's the latest and greatest needs to die. Quality and therefore trust is suffering.
It's not the type of the file but the source of the file that is the issue.
It is also that these sorts of scripts are the source of many untrusted, unsigned and unverified files as well and you cannot necessarily trust the canonical source of them either.
If some random guy gave you some pain killers on the street, would you take them? Probably not. That's exactly what this problem is.