Do not trust anything I write down. I have this horrible habit of not checking sources.

  • 4 Posts
  • 96 Comments
Joined 3 years ago
cake
Cake day: July 3rd, 2023

help-circle







  • 90% of the time, that’s a valid concern, but you can always read the script first.

    It would be a best practice to read any script you want to run on your system. Although the installation instructions tell you to just pipe it into bash.

    And also, if proton wanted to fuck you over, a malicious bash script isnt even a top 10 easy vector. Why trust them with encrypted email if you are suspicious of an install script?

    My concern is not so much proton fucking you over. There are pleny of attack surfaces between you and the server you’re downloading it from.

    Installing software on your system usually lets you check a gpg signature or a hash if you’re downloading a binary. This method provides no such thing.

    A company concerned with security and encryption should know better.