logoalt Hacker News

dfajgljsldkjagtoday at 3:02 AM3 repliesview on HN

It is scary that a text editor can run hidden code just by opening a folder. We traded our safety for convenience and now we are paying the price. Users will always click the button to trust a file if they think it helps them work faster. We cannot blame them when the software design makes it so easy to make a mistake.


Replies

mmh0000today at 3:36 AM

Tooooo be fair

Vim had also had its share of execution vulnerabilities over the years.

https://github.com/numirias/security/blob/master/doc/2019-06...

show 2 replies
EE84M3itoday at 3:03 AM

Doesn't it ask you if you trust a folder when you open it?

show 4 replies
croestoday at 3:44 AM

> We traded our safety for convenience

Not the first time. Same with LLMs.