logoalt Hacker News

guiambrostoday at 12:47 AM1 replyview on HN

Yes, in this specific case.

Obsidian Plugins are still incredibly vulnerable. A compromised plugin will essentially take over your machine. There's no sandboxing of any kind. It's even more insecure than browser extensions (that could steal your auth tokens, but at least don't have unfettered access to your filesystem).

This is really unfortunate. I love Obsidian and am a paid subscriber for many years, but the community plugins needs a security overhaul asap, before someone gets hurt.


Replies

Ferret7446today at 1:39 AM

The same is true for all software on your machine.

show 1 reply