‹ BackHN Continuity

Thread

VSCode's SSH Agent Is Bananas (2025)

310 points · 218 comments · Rapzid

  1. danielklnstein · · focus · HN ↗
    Missing a (2025)

    FYI VSCode's SSH Agent is a godsend for remote development - the "disadvantages" that Fly lists are part of its advantages. I've worked in several teams that have made extensive use of the extension, and it's never been an issue. You can restrict SSH access arbitrarily to ensure whatever security or access guardrails you need.

    1. miohtama · · focus · HN ↗
      “A tool with a purpose of editing files on a remote system can edit files on a remote system.”
      1. varispeed · · focus · HN ↗
        Shock and horror!
      2. devonbleak · · focus · HN ↗
        it's worse than that, last i looked into this - there's functionality in the protocol that allows the remote system to modify files and execute code on the local/frontend system. it really is bananas.

        Edit: there's a security note (still) on the remote ssh extension page:

        Security Note Using Remote-SSH opens a connection between your local machine and the remote. Only use Remote-SSH to connect to secure remote machines that you trust and that are owned by a party whom you trust. A compromised remote could use the VS Code Remote connection to execute code on your local machine.

        <a href="https:&#x2F;&#x2F;marketplace.visualstudio.com&#x2F;items?itemName=ms-vscode-remote.remote-ssh" rel="nofollow">https:&#x2F;&#x2F;marketplace.visualstudio.com&#x2F;items?itemName=ms-vscod...

        1. necovek · · focus · HN ↗
          Reminds me of the old Jenkins protocol which warned about &quot;slaves&quot; getting access to execute code on the &quot;master&quot;: who&#x27;s the master now? ;)
          1. Muromec · · focus · HN ↗
            when slaves became workers and joined the union, the unions became &quot;social partners&quot;. this is how one closes the laptop at 4 and doesn&#x27;t have to suffer vibe-decrees mandating RTO

            seize the control plane.

        2. jasomill · · focus · HN ↗
          This.

          The ability to remotely run arbitrary code on a machine that intentionally gives SSH shell and write+execute access to the filesystem is not a vulnerability just because it&#x27;s a productivity aid to users who want to leverage this access to do bad things on the remote machine.

          A remote access protocol that gives a potentially untrustworthy remote system the ability to execute arbitrary code on the local machine is a serious problem in any scenario where the remote connection is presumed to be a one-way trust boundary.

          Which of course includes any scenario where I myself deliberately run untrustworthy code on the remote, no matter how much I trust the remote itself and its owners.

          1. kevinrineer · · focus · HN ↗
            There&#x27;s also the risk that VS Code is a &quot;trusted&quot; application in many enterprises because developers force it to be. VS Code&#x27;s node runtime (and plugin system) executing somewhat arbitrary Javascript means that any dev servers become vulnerable to exploits you otherwise might not have prepared to defend against [1].

            Otherwise, you could see Javascript running on a server and instantly know something was odd, depending on the server.

            [1] - <a href="https:&#x2F;&#x2F;www.darktrace.com&#x2F;blog&#x2F;darktrace-identifies-campaign-targeting-south-korea-leveraging-vs-code-for-remote-access" rel="nofollow">https:&#x2F;&#x2F;www.darktrace.com&#x2F;blog&#x2F;darktrace-identifies-campaign...

        3. mitjam · · focus · HN ↗
          A surprise waiting to happen if you Remote SSH into an agent sandbox.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.