Lemmy Today
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 2 months ago

VSCode extensions with 9 million installs pulled over security risks

www.bleepingcomputer.com

external-link
message-square
8
link
fedilink
  • cross-posted to:
  • vscode@programming.dev
  • asklemmy@lemmy.ml
50
external-link

VSCode extensions with 9 million installs pulled over security risks

www.bleepingcomputer.com

Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 2 months ago
message-square
8
link
fedilink
  • cross-posted to:
  • vscode@programming.dev
  • asklemmy@lemmy.ml
Just a moment...
www.bleepingcomputer.com
external-link
alert-triangle
You must log in or register to comment.
  • will_a113@lemmy.ml
    link
    fedilink
    English
    arrow-up
    46
    ·
    edit-2
    2 months ago

    Mattia Astorino’s ‘Material Theme – Free’ and  'Material Theme Icons – Free‘ plugins for anyone curious.

    • Harvey656@lemmy.world
      link
      fedilink
      English
      arrow-up
      17
      ·
      2 months ago

      Of course it’s material theme stuff. Smh.

  • merthyr1831@lemmy.ml
    link
    fedilink
    English
    arrow-up
    9
    ·
    2 months ago

    Lmao, Microsoft clearly says themes arent allowed to use scripts and the first thing this jackass does is admit to use obfuscated scripts in his theme. What a dick.

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      That sounds incredibly easy to enforce, why didn’t they?

      • Vendetta9076@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Because Microsoft hates you

      • merthyr1831@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Because people will do the work for them, so why enforce their TOS when they can just say YMMV and have absolutely zero liability if someone’s extension sells your corporate code to the dark web

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          edit-2
          2 months ago

          You can still have zero liability with a simple automated check. A theme is just JSON, so if it’s in the theme category, run it through a JSON parser.

          That would take a bad developer a day to do.

  • lexiw@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 months ago

    The guy is an absolute twat, don’t believe a word he says.

    https://m.youtube.com/watch?v=3wz7YF2as-c&pp=ygUQVGhlbyBnZyBtYXRlcmlhbA%3D%3D

Cybersecurity@sh.itjust.works

cybersecurity@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@sh.itjust.works

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 90 users / day
  • 560 users / week
  • 1.5K users / month
  • 4.76K users / 6 months
  • 32 local subscribers
  • 7.16K subscribers
  • 2.68K Posts
  • 5.12K Comments
  • Modlog
  • mods:
  • Kid@sh.itjust.works
  • Lanky_Pomegranate530@midwest.social
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org