Content
@
https://warpcast.com/~/channel/security
0 reply
0 recast
0 reaction
Paul Berg
@prberg
How big is the security risk if a VSCode extension gets compromised? And is there anything we can do to mitigate the potential risk?
4 replies
0 recast
22 reactions
Juliuss
@julius-eth-dev
hmm I wonder if cursor can be set up to analyze extensions for compromises/malicious code.
1 reply
0 recast
2 reactions
Dean Pierce ๐จโ๐ป๐๐
@deanpierce.eth
Game over for whatever system you're running on. The two main options, keep any sensitive keys off the system you're running vscode on, or run vscode entirely in a VM. I'm mostly doing the former at the moment, maybe migrating to the latter, but that feels like a huge pain in the ass. Also some remote development options.
0 reply
0 recast
1 reaction
MetaEnd๐ฉ
@metaend.eth
Huge, perhaps sandbox vsc or docker it?
0 reply
0 recast
1 reaction
sara
@sari1996
I think thereโs no definitive way to prevent it the best we can do is reduce the risk by installing only trusted extensions.
0 reply
0 recast
0 reaction