Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Until someone thinks that it should follow redirects which probably leads to the same thing that got apt: https://justi.cz/security/2019/01/22/apt-rce.html

Not saying that makes it a bad idea, but importing/downloading trusted code over http(s) is not simple even if the protocol sorta is.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: