Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not about being "smart". It's a completely unnecessary complication in this case.


And a complication that is bad practice because a malicious party can detect the blind handoff to shell and serve malware. e.g. wget file.sh ; vi file.sh and you get safe code curl file.sh | bash and you get malware.

This attack requires a malicious server, but it’s still bad practice.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: