Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You shouldn't.

Github is a gigantic pile of javascript that has to execute on your machine.

`Unzip` doesn't execute anything. If you're really paranoid, use an `unzip` tool written in Rust: https://lib.rs/keywords/zip-archive



No, he really should. Unzip is not the only software interacting when downloading things. A browser has way better sandboxes than the rest of the operating system and desktop environnement.

For instance, here is a vulnerability from the past year leading to code execution on download: https://github.blog/2023-10-09-coordinated-disclosure-1-clic...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: