this post was submitted on 10 Jun 2024
62 points (97.0% liked)

Cybersecurity

5840 readers
251 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
top 7 comments
sorted by: hot top controversial new old
[–] [email protected] 20 points 6 months ago (1 children)
[–] Alphane_Moon 9 points 6 months ago

Medium's initial no-account view is awful though:

Medium

[–] [email protected] 7 points 6 months ago (1 children)

I always found it weird how people are willing to install obscure extensions just like that. For any program that supports them. This doesn't surprise me at all.

That being said I'll go recheck the few I have installed...

[–] johannesvanderwhales 2 points 6 months ago (1 children)

I don't think I realized that the extensions could contain code since most of them are just doing syntax highlighting.

[–] [email protected] 2 points 6 months ago (1 children)

You obviously haven't seen the platformio extension.
It's a beast, turns VSCode into an embedded IDE and programmer for loads of different microchips

[–] johannesvanderwhales 2 points 6 months ago

Yeah I'm not using anything like that. Bit irresponsible of MS to not audit this stuff, then. Lots of businesses allowing users to install vs code extensions freely even if they're otherwise restricted for software installs.

[–] mal3oon 1 points 6 months ago

There was also recently something similar with ComfyUI, where an extensions was embedded with a malware.