I don't really get how VSCode got so popular. You can use a language server perfectly easily with Vim, Emacs, Helix, Sublime, etc. You can customize basically everything in those editors, syntax, etc. You can just alias console commands for all of your build tools with some custom scripts if you need more complex build commands routinely. The git terminal tool works better than any VScode option. And VSCode is slower than all of those.
We already have so many good fast secure polygot customizable text editors. Why run one through Chrome and fill it with extensions for everything that will have arbitrary access to everything?
> We install them without a second thought. They're in the official marketplace. They have thousands of reviews. They work. So we grant them access to our workspaces, our files, our keystrokes - and assume they're only using that access to help us code.
Who is this “we”? I don’t, and don’t know anybody else who does this.
Also, was this article itself written by an AI assistant? If the author is that carefree regarding these extensions, I guess probably.
It's hard for me to fathom that there are capable devs who would pollute their ide with this crap in the first place, malicious or not
Between this and the notepad++ thing... I got to start running programmes with firejail or something.
This seems expected, when you install free, random software, especially from sources known for surveillance/malware/crime.
I'm honestly surprised this issue in general didn't cause nearly every company to immediately ban all AI.
Why do these companies put so much effort into fighting right to repair to avoid IP leaks any halfway serious company could reverse engineer in a week, but on the other hand encourage their employees to vibe all company secrets into the cloud?
> Not just what you're actively working on. Every file you glance at. Every character you type. Captured and transmitted.
Even this reads like an AI extension wrote it.
This is one of the many reasons why I don’t use VS Code, or use any “helpful” AI plugins (or any plugins really).
You all can take vim out of my cold dead hands.
[dead]
[flagged]
Sure, AI tools can do this. However, VS Code is the platform. Why aren't more people worried about running arbitrary VS Code extension that can do the same thing, AI or not?