Hacker News new | past | comments | ask | show | jobs | submit login

No it can be worse than that the install instructions say:

  `curl http://example.com/foo/install.sh | sudo sh`
or if it does request the script by https there is a fair chance that the install script itself will then download by http.

Equally bad is adding a new key to apt/(other package manager) and add a new source then apt-get install (which definitely runs as root).




I blame that on overconfident MacOS X developers not understanding best practices for security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: