Timely, ASUS ships a package that defaults to downloading HTTP content and then executing it in a highly trusted way (BIOS/UEFI and more).
I worry that the business case of "download random stuff online and execute it" is becoming increasingly common (hardware vendors, npm,
rubygems.org, pypi, containers, etc.) and we're going to see a lot more stuff like this.