From: Nico Williams Date: Wed, 07 Oct 2026 20:26:28 GMT Subject: Re: git non-intrusive clone Message-ID: In-Reply-To: On Wed, Oct 07, 2026 at 03:50:43PM -0400, D. Ben Knoble wrote: > Still, definitely worth having the conversation, and I'm glad we > figured it out together. I'm still somewhat interested in what we can > do besides "try to tell folks not to blindly trust downloaded files"… > but that's never going to stop being bad advice :) There have been horror stories about phishing via fake interviews. There is no easy way to ascertain the trustworthiness of such code. Just don't run that code. Use a hosted VM service for this or insist that they use a code pad type web application -- that they don't use those is a red flag. Nico --