i didn’t think it was physically possible, but there’s finally something worse than curl | sh
Replying to @c0dec0dec0de@hachyderm.io
@ciaranmak @Rairii the easiest way to get this LEGO set built is to buy it pre-built from this meth-head who shoplifts them from the local Target, builds them while high and sells them on eBay
Replying to @Rairii@labyrinth.zone
@Rairii @andrewnez that one is for you!
Replying to @Rairii@labyrinth.zone
@Rairii i never understood how curl | sh was worse than just downloading a script and running it tbh .. seems to do the exact same thing
Replying to @Rairii@labyrinth.zone
@Rairii @Li probably still true
Every program that downloads from the internet sends a user-agent header to the server, normally it's program name, version & a bit more text.
A server could use that to detect curl & send a malicious install script that's different from if you downloaded it with Firefox
Replying to @patterfloof@meow.social
Replying to @Rairii@labyrinth.zone
@Rairii Is unfortunate because it's such a baller project
Replying to @ciaranmak@mastodon.ie
@ciaranmak @Rairii this is truly incomprehensible to me. How is a reverse-engineering tool of all the fucking things doing this for their install instructions?! Your users are driven to break things apart and find out how they work. Isn’t this just antithetical to that whole ethos?!
Replying to @c0dec0dec0de@hachyderm.io
@c0dec0dec0de not gonna lie, this sounds like a dream job
Replying to @Rairii@labyrinth.zone
@Rairii this could all be a a Makefile

