Yes but you could make the same case for other means of distribution. It’s not specific to the shellscript installs. You could have a backdoor in a binary too, frankly, it would take even more time to discover it :slightly_smiling_face:. Shellscripts are very transparent.

I wouldn’t want to continue this talk furthermore mainly because it’s quite off-topic. We are discussing something that affects a broad Linux ecosystem, and not this project specifically. If you are security cautious, feel free to run the shellscript line by line (or even build Nix from source), actually it’s quite straightforward and easy to understand. Nobody’s forcing you to pipe it to shell without examining it - but most people don’t care(have enough time), and instructions are generally made for most people.

I’ll leave you with this piece of lecture (just 3 pages long!), talking how it’s impossible to trust any software nor any hardware. It’s a good starting point for further reflection.

There’s also this good video talking about how you are most likely running with multiple backdoors today.

2 Likes