How many production servers have you been responsible for in your lifetime?
"There is no difference to running an executable. "
... There are these following differences.
1. That url, assuming no malicious 3rd-party/nation-state is spoofing the response, could return any different version of the installer resource at any given time.
2. That url might not always be available, for any number of reasons, and how is someone who wants to "discover" this software when they are looking through their available package list?
3. Who knows what that url is "suppose to do" ... there is no signing process, peer review process, nothing, you get whatever the apache server on the other side of that HTTP request wants to give you, and your gonna send that right into your root shell...
4. Unlike a package, sitting in my personal safe, self host, audited, self-verified debian package repository mirror ... this URL might not work tomorrow, it might not work at 3:35am when my primary server took a shit and i need to rebuild the whole stack... who knows what this URL will do in between subsequent runs... it could return 2 different things when I am trying to build a cluster of this product.
"Nobody in their sane mine should curl a script into bash to install a product"
This, so much this.
I was actually extremely excited over a similar product "flynn"... but they have also lost their mind when it comes to installation: https://flynn.io/docs/installation
"Do they not plan on there being an official investigation?"
How do you officially investigate someone stealing your monopoly money?
Where is the FDIC insurance? Exactly what are they suppose to tell the police? The FBI? ... oh thats right, nothing, because they are not a bank, and the only thing "stolen" was some ones and zeroes off a hard-drive.
Seriously though... where is the police report on this? Or any of the other hacked bitcoin exchanges for that matter?
Um... if you don't want anyone to know, why would you EVER send your data to a third party?
All of these "disappearing ink" apps are patently ridiculous, they all have demonstrated security flaws, and they completely ignore the analog gap problem.
What are people thinking when they decide to use this crap?
... "Oh cool, look at me, I am a spy... let me send you something sekret, tee-hee I am sure this other dude running this server is totally cool too so you can send me your sekrets back... tee-hee-hee... nobody will ever know"
So many god damned stupid fucking kids walking all over my fucking lawn these days!