zlacker

[parent] [thread] 0 comments
1. GuB-42+(OP)[view] [source] 2023-09-27 10:41:21
Probably a misguided idea of security. There is nothing wrong with JS itself, in fact, as far as languages go, it is pretty secure due to the attention it gets by being what runs in web browsers.

As for "curl | sudo sh", yeah it looks scary, but it is not worse than downloading a .deb and then doing "sudo dpkg -i your.deb", or installing any downloaded binary on your machine for that matter. You may say something about signatures, but often, the public key you have to trust is on the same website you downloaded the .deb. In all these cases, TLS is the only thing protecting you. Going through a file you don't audit doesn't change anything, and in practice, almost no one does the audit, and few linux boxes have AV scanners.

Don't trust it? Run it a VM, container, or dedicated hardware, this is actually what they are suggesting.

[go to top]