Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cool project.

Since it's not mentioned on the website, what will be your roadmap regarding security?

I feel that all IDEs have security handled as an afterthought, VSCode made some progress but it's far from being there.

I just want to be able to use a code formatting / language extension without having to worry about it subverting my whole computer in a future update.

vscode is halfway there with containerized development, but apparently they didn't intend that to be security measure and they make it clear to only run trusted extensions. I'm guessing there are ways to access host files through the bridge.

It's obvious that we still have to trust extension authors, but an IDE with the correct security sandboxing can limit the blast zone if it gets compromised (leaking a source file vs getting a rootkit installed and ending up releasing compromised updates to production)



Did that happen to you? Sounds scary…




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: