186 karma · joined September 24, 2022
until we do that, VSCode doesn't let us interact with the codebase, so we end up clicking that trust as soon as we open the directory and move on.
When VSCode detects launch commands in ".vscode", It should be rather explicit about running it, like "Trusting this workspace runs the following command on your behalf"
do you mean the machine which is connected through the victim's machine? if so, i should put this in a VM, run and see where it's sending/receiving requests from. i'll do that.
> I maintained a very popular NPM package with 43+M weekly downloads
makes sense why they targetted you, good that you have 2FA enabled.
It doesn't. VSCode dev replied here on it here: https://news.ycombinator.com/item?id=46719712.
But, I don't think anybody pays attention to the workspace trust. When ".vscode" has launch commands, it should rather say, "Trusting this workspace runs the following command on your behalf" or something similar.
they added this back in 2023 (https://news.linkedin.com/2023/april/linkedin-s-new-verifica...), but very less people actually bother to verify with their email, so not having it doesn't always mean it's illegitimate.
should i remove it?
i used the term "consume" and "content" because it covers all forms of content, "reading text", "watching videos" under one blanket term.