Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't, but for install script one can look at least from where the stuff will come. if the download link was using ssl...


I agree, they should use SSL (and don't use a URL shortener, which they don't, but I've seen before).

Ideally it would download a file from Github too, that way you can be sure it's coming straight from the publicly visible open source repo, and you can audit if you want.

But I think the general outrage over this technique is overblown.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: