VS Code extensions are less secure than browser extensions or even NPM packages
baldurbjarnason.com
baldurbjarnason.com
I always think in the back of my mind "if someone compromised nvm-cmp or something we would all be so screwed". That's why I'm very happy to see the core team trying to bring those essential LSP and Completion packages into neovim core.
https://code.visualstudio.com/docs/editor/extension-marketpl...
At least VS Code in a browser is no less secure than the browser itself, at least as far as attacks against the client are concerned.
You're describing what is a feature of remote tunnels, though. Ability to executing code and commands is the entire point.
By default no local code execution is allowed when you open an unknown workspace btw: https://code.visualstudio.com/docs/editor/workspace-trust
Excuse me? Editing code is the entire point. A major, but still secondary, point, is building and running code on the remote machine.
Running code on the client is certainly pointy, but I don’t think it’s “the point” at all.
I don't think so. Building and running on the remote are the point.
Why would I want to remote somewhere just to edit some text files?
Running things on the remote opens up loads of possibilities, from leveraging more powerful hardware to building+running on an architecture different from my local env, including not having to keep a collection of dependencies on my machine and dealing with virtualenvs or whatever is their equivalent in the language I'm coding on.
The problem is that the remote project can run code on the client front end. You can create a brand new cloud machine, give it no particular permissions, run vscode on your laptop, connect to the remote machine via the remote extension, and load some compromised package npm package, and you expect that the damage is limited to the remote machine. And you would be wrong! The npm package can execute code on your laptop or borrow your ssh credentials, and MS doesn’t even consider this to be a bug!
https://github.com/microsoft/vscode-remote-release/issues/66...