‹ BackHN Continuity

Thread

VSCode's SSH Agent Is Bananas (2025)

310 points · 218 comments · Rapzid

  1. 10000truths · · focus · HN ↗
    So a program that is specifically designed to edit files and run arbitrary commands on a remote machine... can do so. Not sure where the bananas part comes in. Sending a binary over SSH/SFTP might sound weird at first glance, but VSCode can't assume that your remote machine can access the wider internet, and it needs a reliable way to bootstrap the agent on the remote. Shipping it over the SSH tunnel is the natural solution.
    1. broken-kebab · · focus · HN ↗
      TRAMP (mentioned in the article) does it without installing anything on remote machine, just SSH, and shell commands. Which sounds more natural to me. Node.js security history, with all due respect, is not shiny. And the problem the author has with VSCode's way, I guess, is not that it can edit files, but that it extends attack surface without real need.
      1. frumiousirc · · focus · HN ↗
        TRAMP actions are also rather slow (high latency). OTOH, tramp-rpc relies on a little tool to run on the remote and is much snappier. This proves there is a better middle ground than TRAMP with nothing and whatever abomination VSCode injects. Basically, busybox with a persistent RPC connection is all one needs.
        1. sl-1 · · focus · HN ↗
          Latency can be managed by having shared connections (for example: <a href="https:&#x2F;&#x2F;tanguy.ortolo.eu&#x2F;blog&#x2F;article42&#x2F;ssh-connection-sharing" rel="nofollow">https:&#x2F;&#x2F;tanguy.ortolo.eu&#x2F;blog&#x2F;article42&#x2F;ssh-connection-shari... ), so handshakes don&#x27;t make everything super slow
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.