• Kairos
    link
    fedilink
    English
    arrow-up
    7
    ·
    6 months ago

    Every time a company bitches that opening ““their”” devices to third party apps because “security” and “malware” I always think of shit like this.

    The Google Play Store has tons of malware. iOS keeps it under wraps with their bullshit entry price and actually okay moderation, but are they a hundred and ten percent sure their signing key or database will never be exploited because there’s a mode on their devices to prevent zero-interaction malware because somehow an SMS being received ends up in the kernel.

    • kippinitreal@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 months ago

      As @Deebster points out, on Android & iOS apps need to ask for permission before accessing sensitive commands beyond the kernel. VisualStudio (as far as as I know) doesn’t have a permissions layer. Also the article also mentions that scrutiny is lenient since VSCode is a Dev tool used by (on average) knowledgeable users.

      100% agree with you, Microsoft is mostly cost cutting/shirking responsibility by not implementing tighter controls on external code on their tools.