Earlier quoted context omitted.
Hello, 2010s called. In 2026, applications, third or even first party, don't need to have full-disk access, and are not given either. They see a jailroot environment. I give full disk access to the terminal app, and a handful of others. 90% of them, nope. At least that's the case in macOS, I'm pretty sure Windows can do that too. Linux of course has had such capability since forever, but I guess most distros you need…
Sadly, Windows cannot do that. Every installed program has full disk access by default. It's very, very difficult to make it not so.
Obsidian plugin was abused to deploy a remote access trojan
141–150 of 241 posts
Re: Obsidian plugin was abused to deploy a remote access trojan
#142Why the hell doesn't the article say WHICH plugins were affected so users can know if they were likely affected?
Re: Obsidian plugin was abused to deploy a remote access trojan
#143Earlier quoted context omitted.
How would that make a difference for plugin security? Almost all plugins are already open source. If you mean for the security of the app without plugins you can currently inspect the app's code in app.js and review third-party audits: https://obsidian.md/security
[flagged]
That's not good enough for open source zealots. That's when you end up being the headliner in an endless flood of blog posts and detailing comments telling everyone you're a 'proprietary evil man'. It's open source or nothing. And how dare you make money.
Re: Obsidian plugin was abused to deploy a remote access trojan
#144A long time ago I figured that "nasty Obsidian plugins" were not a matter of if, but when . So I did the (imho) only sensible thing, and run Obsidian in a sandbox (bwrap). By doing so, I also made sure it runs in a separate networking namespace. For now, I disallow any internet access. The amount of rage I see here is a bit strange, the whole attraction of Obsidian is that you can turn it into a Swiss army knife (tha…
> The amount of rage I see here is a bit strange
Serious question: do you think it is actually obvious and technically accessable to everyday people to have the thought "I should run this in a sandbox" and do it?
Like no this is not some super elite haxxr tool, it's a text editor pretty explicitly advertised as being non-technical-person-friendly.
Re: Obsidian plugin was abused to deploy a remote access trojan
#145Obsidian CEO here. There is a major update coming soon for plugin security. I think it will address many of the concerns people have raised in this thread. It's a hard problem but we are working on it. That said, the headline is misleading. This article is about a social engineering attack that requires the user to actively reject multiple safety warnings in Obsidian. As far as I know this is a proof of concept, I ha…
Re: Obsidian plugin was abused to deploy a remote access trojan
#146Earlier quoted context omitted.
How would that make a difference for plugin security? Almost all plugins are already open source. If you mean for the security of the app without plugins you can currently inspect the app's code in app.js and review third-party audits: https://obsidian.md/security
[flagged]
They are not making excuses, they stated clearly why open sourcing it is tangential to this problem at best, and they're not the only user to call out the hijacking of the thread. They have been quite clear about why they keep it closed source, so I don't know why you're making it sound like they are lying to their users.
Your rant about audits has little to do with the article too. Telling everyone we're going to get rug pulled is exactly the kind of performative FUD that is meant to get a reaction more than anything.
Speaking for myself, I'm going to keep using it, because nothing has come close to the convenience and performance. Would love an open source alternative to prove me wrong, but I haven't seen it.
Re: Obsidian plugin was abused to deploy a remote access trojan
#147Earlier quoted context omitted.
I've never tried to do this or similar in Windows (obviously easy in unix-like environments) but I'm going to bet it's far more trouble than it's worth for 99% of users
On macOS at least those 99% of users are probably installing from the App Store, where apps are sandboxed by default and need to explicitly ask for access to paths outside that sandbox. Even when not installed from the App Store a permission dialogue is popped if an application tries to read from sensitive paths like your photo library.
Re: Obsidian plugin was abused to deploy a remote access trojan
#148Obsidian CEO here. There is a major update coming soon for plugin security. I think it will address many of the concerns people have raised in this thread. It's a hard problem but we are working on it. That said, the headline is misleading. This article is about a social engineering attack that requires the user to actively reject multiple safety warnings in Obsidian. As far as I know this is a proof of concept, I ha…
lol we told you plugins were insecure years ago. I distinctly remember getting flamed in your discord because I said that they had full disk access. Too little too late.
Re: Obsidian plugin was abused to deploy a remote access trojan
#149Earlier quoted context omitted.
You better delete all third-party applications for they are having full disk access.
Hello, 2010s called. In 2026, applications, third or even first party, don't need to have full-disk access, and are not given either. They see a jailroot environment. I give full disk access to the terminal app, and a handful of others. 90% of them, nope. At least that's the case in macOS, I'm pretty sure Windows can do that too. Linux of course has had such capability since forever, but I guess most distros you need…
Re: Obsidian plugin was abused to deploy a remote access trojan
#150Earlier quoted context omitted.
That's horse hockey. Obsidian is not a usable system without community plugins. Folks will reply "but I use it every day without plugins". That position disregards software usability as a formal discipline, along with decades of UX research and standards.
> Obsidian is not a usable system without community plugins. It's horse hockey. Plenty users use the vanilla Obsidian. > Folks will reply "but I use it every day without plugins". Because they do. You're saying that they should lie about their usage to fit your narrative?
They are irrelevant for this dispute, because these problems do not concern them. And the amount of people using plugins because of some real demand is not low.