Comment on A sneaky demonstration of the dangers of curl bash

<- View Parent
ShortN0te@lemmy.ml ⁨22⁩ ⁨hours⁩ ago

This is incorrect. If the update you download is compromised then the signature is invalid and the update fails.

To achieve a compromised update you either need to compromise the update infrastructure AND the key or the infratstructure AND exploit the local updater to accept the invalid or forged signature.

source
Sort:hotnewtop