|
|
|
|
|
by AndrewThrowaway
13 days ago
|
|
I clone some repo from github, open it with default code editor which happens to be Cursor. I am cooked. That is it. It is the same as autorun.exe on some CD - I put some CD in my CD-ROM and my Windows are compromised. You can argue that I should not clone unknown repos, I should inspect each and any file in the repo, look for git.exe or any other suspicious binary and etc. I should not put untrusted CDs or USB sticks into my computer. However the reality of it is that it will not be the user who inspects USB stick in some contained environment, it will be security policy which disables autorun. Same as Cursor should disable this. |
|