Hacker News new | past | comments | ask | show | jobs | submit login

“This installer will run a script to determine if the package can be installed.”

Not “This installer will run a script that installs this package without asking further questions, then terminate abruptly without going through the rest of the install process and giving you a chance to decide exactly where it should go”.




I always read the subtext as "This installer will run a script whose stated goal is to determine if the package can be installed, but y'know, it's a script, and its existence is warranted for doing supposedly helpful yet nonstandard checks that the pkg API-or-something doesn't provide, thus can't be sandboxed, and therefore can do anything else it wants to. Would you like to assume trust and proceed anyway, or would you rather cancel and possibly audit the thing beforehand?".

But that's my paranoid tech background speaking. I can totally understand technical naïveté though.


Zoom and WebEx are certainly taking that subtext but I am pretty sure that is not the intended subtext of that statement. :)


MacOS stupidly runs that script as a user with write permissions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: