When you want to run some code from a non-trusted source like some github repo, what sorts of precautions do you think are sufficient?
#infosec #security #linux #programming
@0x0FFF I think there's some truth to that, with three caveats:
1. There may be communities that I generally trust but may not entirely trust their vigilance in vetting contributions from new devs.
2. There may be some small projects that use techniques I don't entirely understand. (This is especially relevant for anyone still learning a new language.)
3. In my view biggest danger is *thinking* you understand the code when you really don't, so in some sense that's the one I'm most interested in mitigating.
@internic yeah I was really just speaking for myself to be completely honest. I do a lot of code review specifically looking for security vulns in my day job as a pentester, so it’s something I’m pretty confident in. Although like anyone in the world, I’m not free from making a mistake or missing something.
Also, most malicious code isn’t going to pop some magic notification stating it’s malicious. So even if you do run it in a VM or something, I assume it’s then going to be moved to the target system yes? Identifying malicious code as it acts in the system is probably even more difficult than reading the code itself and finding it to be frank. So these users are supposed to be capable of that even though they’re not capable of reading code themselves? I think that’s placing entirely too much theoretical ability on the user, even a technical user or developer. It takes a special set of skills, knowledge, and software, to identify malicious software as it acts on the system.