| ▲ | devonbleak 2 hours ago | |||||||
it's worse than that, last i looked into this - there's functionality in the protocol that allows the remote system to modify files and execute code on the local/frontend system. it really is bananas. Edit: there's a security note (still) on the remote ssh extension page: Security Note Using Remote-SSH opens a connection between your local machine and the remote. Only use Remote-SSH to connect to secure remote machines that you trust and that are owned by a party whom you trust. A compromised remote could use the VS Code Remote connection to execute code on your local machine. https://marketplace.visualstudio.com/items?itemName=ms-vscod... | ||||||||
| ▲ | necovek 2 hours ago | parent [-] | |||||||
Reminds me of the old Jenkins protocol which warned about "slaves" getting access to execute code on the "master": who's the master now? ;) | ||||||||
| ||||||||