top | item 44977583

Show HN: InstallTrust Score – Quantifying software installation security [pdf]

1 points| gunta | 6 months ago |github.com

Quantifying software installation security (seeking reviewers)

1 comment

order

gunta|6 months ago

I've analyzed 100 installation methods across all platforms and created a trust scoring system. Key findings: - curl|sh: Trust Score 18 (critically unsafe) - iOS App Store: Trust Score 98 (near perfect) - 80-point gap between best/worst methods on same platform

  As an engineer writing my first paper, I'm looking for:
  1. Security researchers for technical review
  2. Academic co-authors familiar with supply chain security
  3. ArXiv endorsement (cs.CR or similar categories)

  The framework addresses recent incidents (XZ backdoor, CrowdStrike) and helps teams choose secure installation methods. Would love feedback from the community!