curl + bash is suck and blam the machine. Hope you didn't do a sudo in the last few seconds...
http://www.nastybastard.com/funky-super-installer.sh:
#!/bin/bash
echo "mwuhahahaha"
sudo rm -rf /bootcurl + bash is suck and blam the machine. Hope you didn't do a sudo in the last few seconds...
http://www.nastybastard.com/funky-super-installer.sh:
#!/bin/bash
echo "mwuhahahaha"
sudo rm -rf /bootSure, some are. But most software packages that a user is going to download aren't signed.
I'm a developer and I don't think I've every checked an md5 signature of a jarfile/gem/package I've downloaded. Nor have I ever been in an environment where that was ever mentioned. (Have mostly worked in small to medium businesses--I imagine that bigger orgs or the defense department might do this.)
Things from Google, Intel, MS, VMWare, Spotify, Github, Dropbox, and even f.lux are all signed. Of course YMMV but the trend has been positive.
(A little worrisome is that there are two running Broadcom bluetooth apps that have explicitly revoked signatures...I wonder what that's about.)
EV signed software is usually done off the internet. In our case we use a physical key to sign it offline and then upload.
Is it more difficult to provide your own fake exe installer than to middle-man https that curl examples use?
With signed MSIs and EXEs, you'd need to get your code signed, which is probably more difficult than the web layer.