Noisy "news" like this are actually really good at hiding a lot of real problems. Especially chronic ones that are "old news".
XTL
But also 2.0
Double plus ungood
Maybe you should implement a wellness program.
Worked great for the postal service!
Or is the meat made out of them? He doesn't know.
Well, that post is a straight flush of red flags.
"What do you mean spam is a problem? Just click delete."
The point is that an HTTPS request does not need root permissions. Other steps might, and that's indeed high risk.
That is a good mindset and you should hold on to it. Of course a gui can install a keylogger for you just as easily if not more so.
Trusted install sources, usually called repositories, are the way. Chances of malware exist, but they would require some spectacular shenanigans or conspiracies to set up.
Any instructions that say sudo curl should be thrown out immediately.
It's health and safety gone mad!