this post was submitted on 09 Jun 2024
53 points (100.0% liked)

VS Code

829 readers
1 users here now

founded 2 years ago
MODERATORS
top 5 comments
sorted by: hot top controversial new old
[–] Deebster 23 points 7 months ago* (last edited 7 months ago)

I'd like to see permissions in VSCode plugins, so e.g. I could see that a plugin x can't touch the filesystem or internet and is therefore more likely to be benign.

[–] [email protected] 14 points 7 months ago (1 children)

"A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to "infect" over 100 organizations by trojanizing a copy of the popular 'Dracula Official theme to include risky code. Further research into the VSCode Marketplace found thousands of extensions with millions of installs."

[–] towerful 2 points 7 months ago

The plugin is called "Darcula Official" btw.

There is a more generic theme (for multiple applications) called Dracula.
JetBrains IDE has a theme called Darcula, and there are vscode themes on the marketplace that implement this.

So, it's more than just a typosquat

[–] [email protected] 7 points 7 months ago (1 children)

Every time a company bitches that opening ""their"" devices to third party apps because "security" and "malware" I always think of shit like this.

The Google Play Store has tons of malware. iOS keeps it under wraps with their bullshit entry price and actually okay moderation, but are they a hundred and ten percent sure their signing key or database will never be exploited because there's a mode on their devices to prevent zero-interaction malware because somehow an SMS being received ends up in the kernel.

[–] [email protected] 4 points 7 months ago

As @Deebster points out, on Android & iOS apps need to ask for permission before accessing sensitive commands beyond the kernel. VisualStudio (as far as as I know) doesn't have a permissions layer. Also the article also mentions that scrutiny is lenient since VSCode is a Dev tool used by (on average) knowledgeable users.

100% agree with you, Microsoft is mostly cost cutting/shirking responsibility by not implementing tighter controls on external code on their tools.