Hello!

by

Some code should never touch your real machine.

A recruiter sends a coding challenge. A tutorial says to pipe a script into your shell. A dependency you have never heard of wants a post-install hook.

Each of those runs with your files, your SSH keys, your browser profile, and your password manager sitting right there. Attackers know it — Elastic Security Labs documented a campaign that , which is part of what prompted this project.


Sandfort's answer is boring on purpose: give that work a whole separate computer, make the separate computer cheap to create, and make throwing it away the normal thing to do rather than a chore.

6 views

Add a comment

Replies

Be the first to comment