logoalt Hacker News

fauigerzigerkyesterday at 6:08 PM1 replyview on HN

I use a separate dev user account (on macOS) for package installations, VSCode extensions, coding agents and various other developer activities.

I know it's far from watertight (and it's useless if you're working with bitwarden itself), but I hope it blocks the low hanging fruit sort of attacks.


Replies

bananadonkeyyesterday at 9:26 PM

Check your home folder permissions on macos, last time I checked mine were world readable (until I changed them). I was very surprised by it, and only noticed when adding an new user account for my wife.

show 1 reply