‹ BackHN Continuity

Thread

VSCode's SSH Agent Is Bananas (2025)

310 points · 218 comments · Rapzid

  1. MajesticHobo2 · · focus · HN ↗
    This part of VSCode's architecture is acceptable to me. The reverse direction, where a compromised remote can do whatever it wants to my local machine, is not.
    1. devonbleak · · focus · HN ↗
      it does the reverse direction also. there&#x27;s a security note indicating such on the remote ssh vscode extension page <a href="https:&#x2F;&#x2F;marketplace.visualstudio.com&#x2F;items?itemName=ms-vscode-remote.remote-ssh" rel="nofollow">https:&#x2F;&#x2F;marketplace.visualstudio.com&#x2F;items?itemName=ms-vscod...

      Security Note Using Remote-SSH opens a connection between your local machine and the remote. Only use Remote-SSH to connect to secure remote machines that you trust and that are owned by a party whom you trust. A compromised remote could use the VS Code Remote connection to execute code on your local machine.

    2. Rapzid · · focus · HN ↗
      The part you find unacceptable is the entire point of the article..
      1. MajesticHobo2 · · focus · HN ↗
        Is it? I&#x27;ve read the article twice (yesterday when you posted it and last year when it was first published), and that was not my interpretation.
        1. Rapzid · · focus · HN ↗
          &gt; where a compromised remote can do whatever it wants to my local machine, is not

          It&#x27;s right there in the article, not sure what to say.

          1. MajesticHobo2 · · focus · HN ↗
            It&#x27;s not. Or if it is, it&#x27;s unclear. The article seems more focused on the integrity of remote development servers and deployment targets:

            &gt; Unlike Tramp, which lives off the land on the remote connection, VSCode mounts a full-scale invasion: it runs a Bash snippet stager that downloads an agent, including a binary installation of Node.

            &gt; I would be a little nervous about letting people VSCode-remote-edit stuff on dev servers, and apoplectic if that happened during an incident on something in production.

            1. Rapzid · · focus · HN ↗
              The writing and perhaps messenger isn&#x27;t the best :| It&#x27;s describing people wanting to use VMs for sandboxed development but opening themselves up to risk from the remote machine due to the VSCode SSH Agent protocol allowing the remote server undue access to the local development machine.
              1. wink · · focus · HN ↗
                It&#x27;s buried so deep between &quot;ah yes, of course you know that if you ever used the feature&quot; that I bet the majority of readers might have missed it (me too).
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.