Jump in the discussion.

No email address required.

"Noooo you have to let me obfuscate the frick outta my code so no one can tell what it's doing!"

!codecels he had it coming. There is never any legitimate reason to obfuscate code.

Jump in the discussion.

No email address required.

!fosstards would you run proprietary software written by a schizo who goes edits his posts 5 times an hour? Reminds me of some jeet android rom which added code that nuked your phone if they caught you pirating their paid for features in the free version.

Jump in the discussion.

No email address required.

lol I thought you were exaggerating, but...

https://i.rdrama.net/images/1740857288gpqrxcr05LTfQw.webp

Jump in the discussion.

No email address required.

vlovich123 3 days ago | parent | prev | next [–]

Help me square this circle:

A member of the community did a deep security analysis of the extension and found multiple red flags that indicate malicious intent and reported this to us.

As a reminder, the VS Marketplace continuously invests in security

If you're relying on the community to alert you to the issues in the marketplace, perhaps you're not investing enough in auditing popular extensions yourself?

I would also suggest that the trust model for VSCode is fundamentally broken - you're running arbitrary third party code on client machines without any form of sandboxing. This is a level of security you would not deploy into Azure, so why is "run arbitrary 3p code on someone else's machine" appropriate for VSCode?

>omg someone found some problem for you, therefore, you should dump trillions into auditing extensions

>please lockdown VSCode, make it slower, make it less useful, please please please

Why are reddit nigs so r-slurred?

Jump in the discussion.

No email address required.

yeah they should. are you r-slurred? you like viruses on your computer?

Jump in the discussion.

No email address required.

They already do audit them before making them available. What do you want? Audits every 2 hours? Please pay $30 per month for your VSCode subscription.

:marseyshrug:

Jump in the discussion.

No email address required.

They dont audit shit, dumbass. They run some automated scans but no human at microsoft reviews an extension code unless something like this happens.

Jump in the discussion.

No email address required.

Marketplace protections

The Visual Studio Marketplace employs several mechanisms to protect you from malicious extensions:

Malware scanning

Dynamic detection

Verified publishers

Unusual usage monitoring

Name squatting

Block List

Extension Signature Verification

https://code.visualstudio.com/docs/editor/extension-runtime-security

ThEy AlReAdY dO aUdIt ThEm

@TheOverBeether god you are so fricking dumb

Jump in the discussion.

No email address required.

Thank you for doing my own research.

So, you want Microsoft to scan every line of code for every new extension and every new line of code fro updates for approved extensions.

What do you want? Audits every 2 hours? Please pay $30 per month for your VSCode subscription.

Same point applies.

Jump in the discussion.

No email address required.

Yes lmao. You think google or apple would allow straight up viruses? Dumbass.

Jump in the discussion.

No email address required.

They do. Enjoy your $30 per month subscription. :marseythumbsup:

Jump in the discussion.

No email address required.

:#marseyretard3talking:

Jump in the discussion.

No email address required.

More comments

make it slower

It's already slow as molasses, what's another half-second on top of the eternity it already takes to do anything useful

Jump in the discussion.

No email address required.

>another half a second

Heh. Sure, Gibbies.

:#marseysmug2:

Jump in the discussion.

No email address required.

They really should audit extensions more though. I don't mean like requiring them to be audited before they can get published but just overall more time spent checking out what does get published.

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.



Link copied to clipboard
Action successful!
Error, please refresh the page and try again.