Join Nostr
2025-02-19 08:13:05 UTC
in reply to

Martin Hoffmann on Nostr: nprofile1q…sk9w3 How does this differ from downloading and installing some binary ...

How does this differ from downloading and installing some binary package from a random source? Or even, running “make install” on some source package?

They all can run arbitrary commands on a system.

You could argue curl-pipe-shell is better because it isn’t hiding the dangers in some innocent looking thing.