Readit News logoReadit News
siilats commented on Threat actors expand abuse of Microsoft Visual Studio Code   jamf.com/blog/threat-acto... · Posted by u/vinnyglennon
Tyriar · 18 days ago
VS Code team member here :wave:

As called out elsewhere, workspace trust is literally the protection here which is being circumvented. You're warned when you open a folder whether you trust the origin/authors with pretty strong wording. Sure you may find this annoying, but it's literally a security warning in a giant modal that forces you to chose.

Even if automatic tasks were disabled by default, you'd still be vulnerable if you trust the workspace. VS Code is an IDE and the core and extensions can execute code based on files within the folder in order to provide rich features like autocomplete, compilation, run tests, agentic coding, etc.

Before workspace trust existed, we started noticing many extensions and core features having their own version of workspace trust warnings popping up. Workspace trust unified this into a single in your face experience. It's perfectly fine to not trust the folder, you'll just enter restricted mode that will protect you and certain things will be degraded like language servers may not run, you don't be able to debug (executes code in vscode/launch.json), etc.

Ultimately we're shipping developer tool that can do powerful things like automating project compilation or dependency install when you open a folder. This attack vector capitalizes on neglectful developers that ignore a scary looking security warning. It certainly happens in practice, but workspace trust is pretty critical to the trust model of VS Code and is also an important part to improve the UX around it as we annoy you a _single_ time when you open the folder, not several times from various components using a JIT notification approach. I recall many discussions happening around the exact wording of the warning, it's a difficult to communicate concept in the small amount of words that it needs to use.

My recommendation is to use the check box to trust the parent or configure trusted folders. I personally have all my safe git clones in a dev/ folder which I configured to trust, but I also have a playground/ folder where I put random projects that I don't know much about and decide at the time I open something.

siilats · 18 days ago
How about showing the user what the ide will automatically execute upon install?
siilats commented on Fannie Mae officials ousted after sounding alarm on sharing confidential data   apnews.com/article/fannie... · Posted by u/consumer451
kaycebasques · 3 months ago
> provided confidential mortgage pricing data from Fannie Mae to a principal competitor

It seems like the Fannie Mae data was shared with Freddie Mac. Aren't they both quasi-government organizations? GSEs. So they're both supported by the government but there's a firewall between them to keep some semblance of competition?

siilats · 3 months ago
Having worked on this data since investors buy the loans, the loan level data by definition needs to be public. Even the borrower information is not secret because real estate ownership is public in USA. So I don’t understand what information it could possibly be other than fraud data. I think sharing fraud data is not colluding.
siilats commented on ChatControl: EU wants to scan all private messages, even in encrypted apps   metalhearf.fr/posts/chatc... · Posted by u/Metalhearf
siilats · 4 months ago
I mean USA just went through this when Trump team all got FISA-d and tracked. Chat control is bunch of sha hashes that match. You can basically figure out everyone who has Trump in their WhatsApp contacts and then get every message that matches Trump and no one can tell because it searches for sha(trump) not Trump. It’s perfect tool for surveillance state
siilats commented on ETFs now hold more than $3.1T worth of just top US companies   signalbloom.ai/etf/stats... · Posted by u/GodelNumbering
verteu · 5 months ago
Wealthfront does US Direct Indexing for tax-loss harvesting, they're 25bps/yr.
siilats · 5 months ago
Or you just buy the largest stock in each one of the 7 largest sectors and it pretty much correlates to the sp500. ETF have some nasty hidden fees related to the etf price being more expensive than the basket when you buy and less than the basket when you sell.

Sector Company 1 Company 2 Information Technology Microsoft (MSFT) Apple (AAPL) Financials JPMorgan Chase (JPM) Berkshire Hathaway (BRK.B) Health Care Johnson & Johnson (JNJ) UnitedHealth Group (UNH) Consumer Discretionary Amazon (AMZN) Tesla (TSLA) Communication Services Alphabet (GOOGL) Meta (META) Industrials Boeing (BA) Caterpillar (CAT) Energy ExxonMobil (XOM) Chevron (CVX)

Dead Comment

siilats commented on GOP omnibus bill would sell off USPS's EVs   washingtonpost.com/busine... · Posted by u/dabinat
i80and · 8 months ago
Obviously this is extremely bad and dumb and performative, but putting that aside: who is going to buy them at the needed scale? They're custom purpose-built vehicles for mail delivery, not exactly something I see the marketplace absorbing.
siilats · 8 months ago
I think they only made 93 for the $10bn so it doesnt matter who guys them
siilats commented on Doge cuts to USAid blamed for 300k deaths – most of them children   thetimes.com/us/american-... · Posted by u/mnewme
siilats · 8 months ago
You have to understand that Boston University is not a real school. Even the article says “ She readily recognises the shortcomings of her modelling. The numbers are not recorded deaths, but rather predictions. “They’re modelled numbers and I recognise the limitations that that comes with,” she said. “We don’t have routine data sets that we can measure someone as ‘killed by the US lack of funding’.”. Doge Cuts are necessary so the USA doesnt default on it’s debt
siilats commented on Tornado warnings delayed because of DOGE cuts   mesoscalenews.com/p/torna... · Posted by u/aaronbrethorst
Aeyxen · 9 months ago
The thread keeps circling around the politics, but almost nobody has dug into what actually goes on in the NWS tornado warning pipeline.

It's worth being specific: the National Weather Service operates some of the most robust automation and radar ingest pipelines on Earth, but the final go/no-go warning call is almost always human—often a single overnight forecaster on a console, monitoring a swath of counties. Automation (e.g., Warn-on-Forecast guidance) can surface threats, but the NWS intentionally doesn't have an 'auto-warn' button for tornadoes, because of the asymmetry of false positives (blow credibility, cost lives in the long run).

Budget cuts reduce redundancy and experience in those overnight shifts. When you have only one person monitoring instead of a team of two or three, you get decision fatigue and coverage holes, especially during clustered, multi-cell outbreaks. We've seen near-misses in the past, and every pro-meteorologist I know says they're playing defense against process errors, not just technology failures.

Before we point fingers or blame 'technology/automation' shortfalls, let's quantify the concrete bottleneck: skilled human decision-makers are the limiting reagent; machine learning warning aids are still years away from majority trust.

siilats · 9 months ago
yeah why cannot that guy sit in california or new york in a normal time zone? not like there are tornadoes in every state, its so silly to keep a person at night in an office when weather is good
siilats commented on Corporation for Public Broadcasting Statement Regarding Executive Order   cpb.org/pressroom/Corpora... · Posted by u/coloneltcb
bhouston · 9 months ago
The US is so weird right now.

You have a President who is ordering the defunding of tons of groups (universities, media, aid, institutes) while not clearly having that authority and often doing so for what he views as ideological crimes.

Also arresting and trying to deport people for things that are not clearly crimes (newspaper op-eds, etc) and without due process.

Very strange times.

Right now I have some faith the courts in the US will stand up to this and get the US back on track but I worry that dam may not hold forever.

Saving grace is that his is not widely popular, although that is more for his tariff moves than for the others.

siilats · 9 months ago
The anti trump money groups have infiltrated HN or you really think the government today should be spending money on CBS?
siilats commented on Self-Driving Teslas Are Fatally Rear-Ending Motorcyclists More Than Any Other   fuelarc.com/news-and-feat... · Posted by u/NotInOurNames
lightedman · 10 months ago
"It’s not just that self-driving cars in general are dangerous for motorcycles, either: this problem is unique to Tesla. Not a single other automobile manufacturer or ADAS self-driving technology provider reported a single motorcycle fatality in the same time frame."

Doesn't matter when mileage isn't what's being compared - it's whether or not others have caused the same problem - PERIOD.

siilats · 10 months ago
so if the other cars have 5x less miles on autopilot compared to tesla you expect to see 0 crashes even though the probability of a crash is the same

u/siilats

KarmaCake day46June 7, 2010View Original