The agent is supposed to run on a remote dev box. The purpose is to make the remote machine an extension of your local one, to run extensions, containers, install packages, test deployments, forward ports and tons more. Tunneling is part of the feature set. If you are installing it on production servers and are surprised by its behavior that’s on you.
> # Security Note
>
> Using Remote-SSH opens a connection between your local machine and the remote. Only use Remote-SSH to connect to secure remote machines that you trust and that are owned by a party whom you trust. A compromised remote could use the VS Code Remote connection to execute code on your local machine.
From <a href="https://marketplace.visualstudio.com/items?itemName=ms-vscode-remote.remote-ssh" rel="nofollow">https://marketplace.visualstudio.com/items?itemName=ms-vscod...
It's like giving away a gun that explodes in your face if you shoot it in anger, but with a prominent label on the box that says 'WARNING: Will Malfunction!'. And then heavily promoting it.
why would anyone connect with this to an unknown/untrusted machine? it's more like giving away a gun that will shoot you if you point it at your own head and pull the trigger
Because systems are made of components based on assumptions. The owners of a sandboxed LLM development environment provides isolated VM workstations, and allow access via SSH, with things like X forwarding disabled. IP connections are dynamically permitted via access tickets and time ranged 2FA.
Separately, developer becomes a VSCode user. Risk as assessed based on them developing on their Dec machine, accepted.
Developer then opens a ticket to use LLM for a project. Uses VSCode SSH Agent. Agent creates exfil tooling on workstation and reverse shells their box. Agent reads unauthorised data which possibly has LLM subversion triggers, or deletes data, maybe opens connections to C2 service. LLM agent pivots to cloud inference and continues to lateral movement.
The assumptions of systems composition are violated by VSCode. That's why its SSH Agent needs to be blocked.
binlog · · focus · HN ↗
angry_octet · · focus · HN ↗
not_a_bot_4sho · · focus · HN ↗
> # Security Note > > Using Remote-SSH opens a connection between your local machine and the remote. Only use Remote-SSH to connect to secure remote machines that you trust and that are owned by a party whom you trust. A compromised remote could use the VS Code Remote connection to execute code on your local machine.
From <a href="https://marketplace.visualstudio.com/items?itemName=ms-vscode-remote.remote-ssh" rel="nofollow">https://marketplace.visualstudio.com/items?itemName=ms-vscod...
Big bold text and everything
angry_octet · · focus · HN ↗
ikrenji · · focus · HN ↗
angry_octet · · focus · HN ↗
Separately, developer becomes a VSCode user. Risk as assessed based on them developing on their Dec machine, accepted.
Developer then opens a ticket to use LLM for a project. Uses VSCode SSH Agent. Agent creates exfil tooling on workstation and reverse shells their box. Agent reads unauthorised data which possibly has LLM subversion triggers, or deletes data, maybe opens connections to C2 service. LLM agent pivots to cloud inference and continues to lateral movement.
The assumptions of systems composition are violated by VSCode. That's why its SSH Agent needs to be blocked.