Earlier quoted context omitted.
Seriously, what is the threat model here?
There is no threat model that doesn't also apply to pretty much every other distribution method. It's just people who have internalized "don't paste commands from the Internet into your terminal" and aren't thinking about exactly what makes pasting commands from the Internet into your terminal dangerous, and how that applies to this specific case.
Elevated error rate across multiple models
291–293 of 293 posts
Compromised web server, since they don't tend be as secure. Signed packages are safer as signing keys are generally more secured than web servers.
Re: Elevated error rate across multiple models
#292Earlier quoted context omitted.
Both of them provide that option. I've never installed rust without a package manager. Why would I?
> Why would I? Because then you can install it without depending on a package manager?
What an odd comment.
"You can mine and refine your own iron ore so you can have a metal fork without depending on modern infrastructure."
Sure, but why.
Re: Elevated error rate across multiple models
#293Earlier quoted context omitted.
> Why would I? Because then you can install it without depending on a package manager?
What an odd comment. "You can mine and refine your own iron ore so you can have a metal fork without depending on modern infrastructure." Sure, but why.
It doesn't matter why. Many people choose to do it that way. And if you want them to use your software, you need to enable them.
But to answer your question directly - I suspect they simply don't care, and just take the easiest way.