Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
labster
1y ago
0 comments
Share
You know the rules, and so do I.
0 comments
default
newest
oldest
dv_dt
1y ago
I know I prefer my exploits to come from opaque corners of package formats or docker layers as bofh intended. The more indirect handoffs of trust the merrier.
Timber-6539
1y ago
Docker is at least sandboxed by default and requires sudo password to run commands.
dv_dt
1y ago
There are advantages to docker, but also disadvantages. Definitely the same w/ "curl | sh" That's all I was trying to allude to, tongue in cheek.
freeone3000
1y ago
But it requires sudo or effective-sudo to run
any
command, making such a measure worthless
j
/
k
navigate · click thread line to collapse