4 ms·
TL;DR: risk is probably pretty low I used to struggle with this too, but now I look at it this way: you're always at risk of being breached when connecting to
by rowbin 3y ago
TL;DR: risk is probably pretty low
I used to struggle with this too, but now I look at it this way: you're always at risk of being breached when connecting to the Internet (zero days in Browser, Router, maybe IoT devices on the local network, supply chain attack of some installed software, router, ...). Everything you add to your system/network adds attack surface. But: somewhat popular github projects are usually low risk, because 1) enough people are looking into it to be reasonably sure there's nothing funny in the code base, 2) it's not big enough to be an instetesting targeted for malicious actors.
I think a big part of why it feels scary is the unpredictability you mention. You don't know how you would be compromised and whether you would even notice. Sure you could get comprised and then spread the infection, but it's extremely hard to build malware like that. The much more likely scenario is the that the malware tries to steal crypto or encrypts your files. The chances that something really bad would happen are very slim (Do you even have large amounts of crypto? Do you not have any backups of important files?). In the end that's just a risk you'll have to live with (when connecting to the Internet) just like you're at risk of getting hit by a car when going outside.