A good day not to be using Electronjs trash.
Electron has nothing to do with the exploit here. A Vim plugin would have just as much ability to run malware.
GitHub confirms breach of 3,800 repos via malicious VSCode extension
261–270 of 488 posts
Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#262Why does a company in GitHub's place allow employees to install random VSCode extensions?! That seems grossly irresponsible.
Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#263Vs code extensions have been terrifying for a long time. Such a wild and obvious attack vector. I'm constantly getting pop ups in vscode to install an extension because it recognizes a certain file type. It's 50-50 whether that extension is owned by a company or some random dev. Some of these have millions of installs and on first glance appear to be official company owned extensions. I'm at a point in my life where…
Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#264Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#265Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#266Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#267Vs code extensions have been terrifying for a long time. Such a wild and obvious attack vector. I'm constantly getting pop ups in vscode to install an extension because it recognizes a certain file type. It's 50-50 whether that extension is owned by a company or some random dev. Some of these have millions of installs and on first glance appear to be official company owned extensions. I'm at a point in my life where…
I don't use VSCode, but doesn't their plugin ecosystem indicate if the plugin is MSFT-approved?
Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#268Earlier quoted context omitted.
The problem extends far beyond VS code. All extensions and executable code has the same problem. There was a case where Disney was hacked because an employee installed a BeamNG mod that had bundled malware. A company that wants to remain secure would have to employ strict restrictions on installing software. Only installing npm packages and plugins from an internal preapproved repo for example.
Funnily enough a lot of this "extension sprawl" is caused by the _difficulty_ of installing tools on locked down Windows machines. I recently moved to a locked down SoE and instead of being able to use regular tools (which require a lengthy negotiation process to install) I now use extensions for absolutely everything, _because_ they're not currently policed in the same way...
Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#269Why does a company in GitHub's place allow employees to install random VSCode extensions?! That seems grossly irresponsible.
You're assuming they allow it, but it might be against policy.
Problem is: most employees don’t care to read these. Although I’m sure something like this could have been checked for during commit.
Re: GitHub confirms breach of 3,800 repos via malicious VSCode extension
#270Earlier quoted context omitted.
I think the chart is still from the Steve Jobs era, who definitely was known to be a micromanager.
There’s an interview with someone talking about Steve having an extreme melt down rage about the header not being technically centered in one spot on the Apple page. I want to see his reaction trying to type a message on the iPhone keyboard from anytime in the past 7 years. Or navigate the random nonsensical grouping of stuff in settings that got so out of control they added a search bar or watch a pip video or reall…