‹ BackHN Continuity

Thread

VSCode's SSH Agent Is Bananas (2025)

310 points · 218 comments · Rapzid

  1. 10000truths · · focus · HN ↗
    So a program that is specifically designed to edit files and run arbitrary commands on a remote machine... can do so. Not sure where the bananas part comes in. Sending a binary over SSH/SFTP might sound weird at first glance, but VSCode can't assume that your remote machine can access the wider internet, and it needs a reliable way to bootstrap the agent on the remote. Shipping it over the SSH tunnel is the natural solution.
    1. bobtheborg · · focus · HN ↗
      I think the actual concern, not well expressed in the blog post, is the fact that node and vscode server are installed on, for instance, a prod machine that (probably) should be very tightly controlled in terms of what software is installed and running. You don't want to unwittingly add to the attack surface
      1. pstuart · · focus · HN ↗
        Fair enough, but running VSCode on a prod machine is also bananas.
        1. K0IN · · focus · HN ↗
          agree, but do you think every dev you know konws this?

          also "i just want to edit a config file and i want a nice ui", is how you get there.

          1. doc_ick · · focus · HN ↗
            Expecting vscode to police every single dev using it instead of a company is bananas.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.