chebra

joined 7 years ago
[–] chebra@mstdn.io 3 points 1 year ago (1 children)

@mihor oh oh, someone drank too much russian kool-aid

[–] chebra@mstdn.io 9 points 1 year ago

@danielquinn @Tomkoid That might change very quickly after Gitlab finds a buyer.

[–] chebra@mstdn.io 1 points 1 year ago

@gomp Yes but the point is that it comes from a different place and a different time, so for you to execute a compromised program, it would have to be compromised for a prolonged time without anyone else noticing. You are protected by the crowd. In curl|sh you are not protected from this at all

[–] chebra@mstdn.io 1 points 1 year ago (2 children)

@gomp You mean, as seldom available as every apt install ever? https://superuser.com/a/990153

[–] chebra@mstdn.io 1 points 1 year ago (4 children)

@gomp Why would you be taking the signature from the same website? Ever heard of PGP key servers?

[–] chebra@mstdn.io 2 points 1 year ago (6 children)

@gomp try comparing it with apt install, not with downloading a .deb file from a random website - that is obviously also very insecure. But the main thing curl|sh will never have is verifying the signature of the downloaded file - what if the server got compromised, and someone simply replaced it. You want to make sure that it comes from the actual author (you still need to trust the author, but that's a given, since you are running their code). Even a signed tarball is better than curl|sh.

[–] chebra@mstdn.io 2 points 1 year ago (1 children)

@Sethayy cool, go ahead. But still nobody made that take, so ... you are arguing with the wind.

[–] chebra@mstdn.io 2 points 1 year ago (3 children)

@Sethayy nobody made that take...

[–] chebra@mstdn.io 2 points 1 year ago (3 children)

@over_clox The lack of redistribution is what's causing projects to disappear and die, vendor lock-in, walled gardens, bricked devices.. you clearly have no idea what you are talking about

[–] chebra@mstdn.io 2 points 1 year ago (5 children)

@over_clox Which means it's not open-source, silly, because open-source explicitly means you can redistribute it.

[–] chebra@mstdn.io 0 points 1 year ago (1 children)

@delirious_owl Oh wow, look at this guy, he just solved it all! Now we can finally put all the climate change worries behind. Thanks for saving the world.

[–] chebra@mstdn.io 0 points 1 year ago (1 children)

@delirious_owl @__

If life gives you lemons, make lemonade. If you kitchen is on fire, grill sausages. If your crops are dying, eat dirt. I mean the positive attitude is nice, but it does break down a bit towards the end...

view more: ‹ prev next ›