If anyone is at all concerned with their privacy, they should never blindly run a script like that.
I cannot seriously listen to anyone who "cares" about privacy, then asks their users to download and execute unknown code.
Or are you seriously going to tell me that you feel you can't trust a 75 line script you just fully vetted, but you can trust, say, the Linux kernel, despite the fact that you didn't manually parse the millions of lines of code in it? If that really is your argument, then I can only imagine that you stop on green and go on red out in the real world, because that's pretty damn fucked up.
As well, OSX won't let me execute unsigned binary code from unknown developers, unless I manually overwrite it.
The pattern of piping a script from curl and executing it, isn't one I'd expect a site that claims to care about people's privacy to champion. This seems to be exactly what you are saying too.
Why didn't the site owner say, 'curl this script', inspect it, here is the md5 of what it should be, then execute it? Why the cuteness of the direct download and execute? That is my critique.
I just don't get the mentality here sometimes; someone creates a helpful script, puts the source code on their site for you to read and study, and the first instinct is to assume they have malicious intent before even taking a few minutes to read over it first. Hell, I'm no programmer but I know enough about the basics to follow exactly what the code does. It took me all of five minutes to decide that it flips two switches and nothing more. That the programming gods here can't or won't do that is telling.
I get being paranoid about random scripts, but this one is on display for all to see before running. There is literally nothing hidden, yet you all act as if the author is trying to secretly take over your machines. It would be funny if it wasn't so pathetic.