Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Would this be better if the pasted command included some checksum which was checked before piping into the `sh`? Can anyone who's better at bash than me give an example of how this could work in a relatively cross-platform way?


You would need to have a GPG signature with a well-known public key that is verified before executing the code.


Sorry, can you explain why? If the checksum is provided (as part of the sh snippet) by the website with the SSL certificate, isn't that enough reassurance?


If the snippet and the download are on the same site, then whoever controls that site at the moment can provide an accurate checksum of whatever malware they want to host. A signature is an improvement because it can give you some confidence that the current controller is the same as the original controller.


> Would this be better if the pasted command included some checksum which was checked before piping into the `sh`?

hashpipe does exactly that:

https://github.com/jbenet/hashpipe




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: