How is that any different than installing any opaque binary app?
It all comes downs to whether you trust the source.
At least with the "curl http://xxx | sh" method you can also examine the contents of the script before running it, and even opt to run it after downloading it and checking it locally.
With binary apps off of internet sites, which is what people install and use dozens of times a month, no such luck.
In this case, you have no idea if the connection is MITM'd because of http. You must assume the source untrustworthy, because you don't know who it is. Additionally, assuming the page's source (from which you copy this command) is over http, you must assume the website has compromised (e.g.) your clipboard on copy and you're pasting in malicious unicode characters or whatever. People should have an inherent distrust of binary blobs, too, for whatever that's worth. Same caveats over serving the download over http, with the added benefit of not being able to read the source (necessarily), with the added bonus of now having to assume the build machine has not been compromised.
>People should have an inherent distrust of binary blobs, too, for whatever that's worth.
All you said are true for binary blobs as well. The page could be MITM, etc.
"curl xxx | sh" style deployment has all the same disadvantages of binary blogs, but has the added advantage that you can download and check the code before executing it.