• koper@feddit.nl
    link
    fedilink
    English
    arrow-up
    22
    ·
    12 days ago

    I don’t want to trust a website, which is susceptible to typos and lookalikes (see e.g. putty.org) and relies on countless other services that can inject malware.

    Code signing was creates for this reason: ensure that the program is authentic and unaltered. Package managers do this perfectly.

    • flying_sheep@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 days ago

      100%. I’m just saying that on Windows an Mac, the inferior “download an installer” model is still prevalent, and that |sh is as safe as that.