Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unless you've audited the source, a manual install isn't any better.


No. With a curl install, you cannot audit the source. You cannot know if you have been served the same content as someone else.

You cannot look at version history, check a signed package, etc. etc.

If someone wants to root just a few select machines, you would want people to do a curl install.


If you're going to manually audit the source, you can curl into a file then run bash on it. If you're not going to read the code anyway, there's no harm in curl|bash.


Yes there is, there's a lot of harm, see my comment above.


Hence why I merely opposed actively encouraging this pattern.

I can't stop people from doing potentially dangerous things, but I don't have to promote those things, either.


I don't think the other way is inherently any safer, because people don't tend to actually audit their sources to begin with.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: