Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Only to be thrown out of the windows with a plain "curl | sh".


curl | sh is more prevalent in Linux where you can expect a stable ABI from the kernel and sometimes GNU libc. No such things in BSD land. Packages are built against a release always. They don't maintain binary compatibility.


Hardly an argument against random shell scripts execution, quite often elevated.

Not everyone installs only what is available in pkgsrc.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: