• theunknownmuncher@lemmy.world
    link
    fedilink
    arrow-up
    3
    arrow-down
    10
    ·
    edit-2
    6 hours ago

    Nah. Nothing is perfect of course, but normalizing executing software sourced from random, untrustworthy websites will always be objectively worse than curated repos.

    • Cypher@aussie.zone
      link
      fedilink
      arrow-up
      11
      arrow-down
      1
      ·
      edit-2
      6 hours ago

      It is hardly a random untrustworthy site, it is the software publishers site. There is no reason that a package repo can’t suffer a similar attack.

      Your confidence is entirely misplaced.

      • theunknownmuncher@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        12
        ·
        edit-2
        6 hours ago

        Oh I guess I should totally put my confidence in random sketchy websites. Great point!

        It literally doesn’t matter if it’s a publisher site or not, users can’t tell the difference and it normalizes clicking links from a web search and running whatever software download the user sees first.

        • Cypher@aussie.zone
          link
          fedilink
          arrow-up
          6
          ·
          6 hours ago

          Go on then, explain to me how the well known software publishers website is random and sketchy.

          • theunknownmuncher@lemmy.world
            link
            fedilink
            arrow-up
            1
            arrow-down
            12
            ·
            edit-2
            6 hours ago

            I feel like you’ve demonstrated very effectively how users lack the skills to understand what they are reading online 😂

            • Cypher@aussie.zone
              link
              fedilink
              arrow-up
              10
              arrow-down
              1
              ·
              6 hours ago

              It isn’t a random, sketchy or inherently untrustworthy site.

              You shouldn’t have any issue explaining how you would go about verifying that a software repo is trustworthy and how that differs from verifying a website.

              Unless you don’t actually know what you’re talking about…