logoalt Hacker News

layer8 • yesterday at 3:21 PM • 2 replies • view on HN

I push binaries from untrusted sources through VirusTotal before running them. Piping a Bash script from curl bypasses that. Furthermore, such Bash scripts, when they aren’t self-contained, make security checks more difficult than a self-contained archive, installer, or binary, even when downloading the script without immediate execution.


Replies

parsimo2010 • yesterday at 3:56 PM

You could always curl the install script, and modify it to run the virus scan in between the build and install steps.

Iolaum • yesterday at 3:24 PM

Nothing is stopping anyone from pointing their agent to that script to review and audit it before running it.

➕ show 1 reply