Hacker News new | past | comments | ask | show | jobs | submit login

Why does this link need to be shortened at all?



Since the original one is really long; would make the install script even less readable.

Also, git.io allows only shortening github repos; so there should be no harm


> Since the original one is really long; would make the install script even less readable.

Really?

Who do you think your target audience is? I'm sorry, but this is not "really long":

    https://github.com/supermarin/Alcatraz/releases/download/1.0.1/Alcatraz.tar.gz
If you're telling people to run random commands in their terminal that lead to local code execution, then you should trust that they can read a goddamn URL.

If you don't think your user base can read URLs, then you shouldn't be telling them to launch the terminal and run your code.


You are providing an HTTP link to git.io, so it cannot be verified whether I am connecting to the real git.io. This means an attacker can fake himself being git.io very easily (a classic man-in-the-middle attack).

It doesn't matter if git.io can only shorten git urls, as git.io will never be involved in a potential attack.

Using a link shortener is okay, but use one that supports HTTPS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: