Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How come do you trust the package of Rust from Rust but you don't trust the `sh` install script from Rust?


This specifically isn't an issue of trusting them with my system, it's that a shell script can give a shit all over a system without a good way to undo it, even if it was well-intentioned.

Package managers are modern technology, they exist because they can track what files were placed where, and can remove them cleanly when given an uninstall command.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: