Remix.run Logo
Config Files That Run Code: Supply Chain Security Blindspot(safedep.io)
41 points by signa11 6 hours ago | 5 comments
Tangurena2 an hour ago | parent | next [-]

I've heard about these attacks but never really had the time to understood what was happening. Some of our junior devs use VS Code, so now we have something to point them at.

embedding-shape 2 hours ago | parent | prev | next [-]

Is this why Windows Defender is prompting me 2-3 times a day to submit my codex/config.toml to Microsoft for "malware analysis"? I've said no every time so far, since my first thought is "What could even be hidden there?" when I see the dialog yet again, I'm guessing Microsoft would love to see how people use their competitors' products though.

lstodd 2 hours ago | parent [-]

You might as well click yes, since it's all been uploaded as telemetry anyways.

IcyWindows an hour ago | parent [-]

Citation needed

bpt3 an hour ago | parent | prev [-]

It's far from a blindspot. People have been yelling about this from the rooftops for the last several years.

No one cares about security. People used to care for a fairly short period of time after something bad happened to them, but even that seems to have gone by the wayside as breaches, leaks, and use of exploited code has become normalized.