89
submitted 3 months ago* (last edited 3 months ago) by graphito@sopuli.xyz to c/foss@beehaw.org

cross-posted from: https://jlai.lu/post/8476122

Zed on Linux is out!

you are viewing a single comment's thread
view the rest of the comments
[-] davehtaylor@beehaw.org 38 points 3 months ago

Might be neat. Might check it out. But devs really need to stop asking me to install things by curling a script and piping it into my shell. There are better ways to do this. Doing this leaves a massive possible attack surface.

[-] erwan@lemmy.ml 4 points 3 months ago

No matter how they package it, running a binary downloaded from Internet has the same attack surface

[-] tesseract@beehaw.org 5 points 3 months ago

You are right, except for one detail. Package managers almost always validate the packages using digital signatures, to avoid man-in-the-middle attacks. You don't need to trust the network anymore. Shell scripts piped to a shell don't have that protection. You still have to trust the developers and maintainers, though.

[-] msage@programming.dev 2 points 3 months ago

Shell scripts have md5 signatures

load more comments (1 replies)
this post was submitted on 10 Jul 2024
89 points (98.9% liked)

Free and Open Source Software

17901 readers
1 users here now

If it's free and open source and it's also software, it can be discussed here. Subcommunity of Technology.


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS