logoalt Hacker News

MajesticHobo2yesterday at 9:52 PM2 repliesview on HN

This part of VSCode's architecture is acceptable to me. The reverse direction, where a compromised remote can do whatever it wants to my local machine, is not.


Replies

devonbleakyesterday at 10:44 PM

it does the reverse direction also. there's a security note indicating such on the remote ssh vscode extension page https://marketplace.visualstudio.com/items?itemName=ms-vscod...

Security Note Using Remote-SSH opens a connection between your local machine and the remote. Only use Remote-SSH to connect to secure remote machines that you trust and that are owned by a party whom you trust. A compromised remote could use the VS Code Remote connection to execute code on your local machine.

Rapzidyesterday at 11:04 PM

The part you find unacceptable is the entire point of the article..