When you want to run some code from a non-trusted source like some github repo, what sorts of precautions do you think are sufficient?
#infosec #security #linux #programming
@mathaetaes So take it to be implicit here that the intent is to mitigate the risk beyond whatever you can do by looking at the code. (Honestly, I think people overestimate their ability to spot malicious code.)
@internic Fair point, though I find vulnerabilities and shenanigans in source code for a living. :)
I do have a VM for "questionable" software... though that's usually used for software that I trust, but that I don't trust will clean up after itself when I try to remove it. Autodesk software is the primary vendor for that VM...