Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I didn't say it was. The poster was commenting on the arguments that enforce HTTPS and TLS1.2, and they were wrong - those arguments are not security theater at all.

As for 'is curl | sh safe?' I am done arguing with people who don't understand that it's absolutely fine.



the poster was not suggesting those things are not legitimate and secure maneuvers ... the poster is suggesting that you can have the most rock solid and authentic transport mechanism and - in spite of that - can still end up compromising your system by running the wrong thing.

> As for 'is curl | sh safe?' I am done arguing with people who don't understand that it's absolutely fine.

eep.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: