Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Access Denied

    November 2, 2025

    don’t peel off that screen protector on the iQOO 15

    November 2, 2025

    Pay for Apple TV+ Annually to Avoid the Recent Monthly Price Increase

    November 2, 2025
    Facebook X (Twitter) Instagram
    Sunday, November 2
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Trump’s swift demolition of East Wing may have launched asbestos plumes

      November 2, 2025

      Closing Windows 11’s Task Manager accidentally opens up more copies of Task Manager

      November 2, 2025

      Elon Musk on data centers in orbit: “SpaceX will be doing this”

      November 2, 2025

      2026 Hyundai Ioniq 9: American car-buyer tastes meet Korean EV tech

      November 2, 2025

      AT&T sues ad industry watchdog instead of pulling ads that slam T-Mobile

      November 2, 2025
    • Science & Education

      In 1925, seven students went 60 hours without sleep—for science

      November 1, 2025

      Food scraps could power future airplanes

      November 1, 2025

      We sharpened the James Webb telescope’s vision from a million miles away. Here’s how.

      November 1, 2025

      A toxicologist explains when you can safely cut the moldy part off food, and when it’s best to toss it

      November 1, 2025

      Chimps ‘think about thinking’ in order to weigh evidence and plan their actions, new research suggests

      November 1, 2025
    • Mobile Phones

      don’t peel off that screen protector on the iQOO 15

      November 2, 2025

      Major chipmaking breakthrough aimed at returning U.S. dominance to chip production

      November 2, 2025

      Sony’s LYT-910 leak: near 1-inch 200MP sensor to power 2026 flagships

      November 2, 2025

      Dreame launches V3000 Aura 4K Mini LED TVs with 2800 nits, Dolby Atmos & AI features

      November 2, 2025

      Standard iPhone 18 could pack 50% more RAM than iPhone 17

      November 2, 2025
    • Gadgets

      Pentagon will reportedly award SpaceX a $2 billion contract to help develop the ‘Golden Dome’

      November 1, 2025

      A deep dive into humankind’s search for alien life

      November 1, 2025

      Ayaneo’s first smartphone could have physical shoulder buttons

      November 1, 2025

      Italy will be the latest country to require age verification for porn sites

      November 1, 2025

      How to watch the 2025 MLB World Series without cable

      November 1, 2025
    • Gaming

      New Hades 2 Patch Expands The Ending

      November 2, 2025

      Typing Games Are Cool Again Thanks To Wildly Unexpected Twists

      November 1, 2025

      Xbox Elite Series 2 Controller On Sale For Lowest Price This Year

      November 1, 2025

      Fortnite – New Weapons In The Simpsons Season

      November 1, 2025

      Everything New In Fortnite’s The Simpsons Season

      November 1, 2025
    • Cars

      Access Denied

      November 2, 2025

      Mercedes-Benz Sprinter: The Origin Story of Merc's Ubiquitous Van

      November 2, 2025

      New & Used Avg. Transaction Prices (ATPs) from Edmunds | Edmunds

      November 2, 2025

      Access Denied

      November 2, 2025

      Access Denied

      November 2, 2025
    • PC Accessories

      Pay for Apple TV+ Annually to Avoid the Recent Monthly Price Increase

      November 2, 2025

      Blood Oxygen Monitoring Returns to Recent US Apple Watches with Software Updates

      November 2, 2025

      Apple Unveils New iPhone 17 Lineup, Updated Apple Watches, and AirPods Pro 3

      November 2, 2025

      Follow This Advice Before Switching to a New iPhone 17

      November 2, 2025

      When to Trust AI Tech Answers (And When to Call Us)

      November 2, 2025
    ToolcomeToolcome
    Home»PC Accessories»Stop Hard Coding Certs, Tokens And Other Authorization In Your VS Code Extensions!
    PC Accessories

    Stop Hard Coding Certs, Tokens And Other Authorization In Your VS Code Extensions!

    November 2, 2025No Comments2 Mins Read2 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Bad Coder!  Stop It!

    It may be convenient, but if you are designing custom VS Code extensions do not code in anything you don’t want people to get access to!  There are currently over 500 VS Code extensions with hard coded tokens, credentials, encryption keys, certificates, and other ways of automatically authenticating to be found online.  This is not just bad practice, but thanks to the convenient way that VS Code extensions automatically update it can become an ongoing security nightmare.

    Wiz Security found that more than 100 of these extensions contained the authentication necessary to be able to update the extension itself which, if they took advantage of it, would have allowed them to automatically infect around 150,000 users.  All they would have needed to do is edit in some nasty code to the extension and upload it.  Any machine running that extension would then automatically update that extension and infect it with whatever was added.

    There is a good chance that at least some of this is thanks to vibe coding and not just laziness, as extensions for generative AI platforms were one of the more commonly discovered in their tests.  Thankfully Microsoft implemented a secret scraping process for VS Code extensions yesterday, just before this research was published so the vulnerable parties are safe now, though their extensions probably no  longer function properly.

    You should not depend on this; simply don’t ever code in secrets!

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    Pay for Apple TV+ Annually to Avoid the Recent Monthly Price Increase

    November 2, 2025

    Blood Oxygen Monitoring Returns to Recent US Apple Watches with Software Updates

    November 2, 2025

    Apple Unveils New iPhone 17 Lineup, Updated Apple Watches, and AirPods Pro 3

    November 2, 2025

    Follow This Advice Before Switching to a New iPhone 17

    November 2, 2025

    When to Trust AI Tech Answers (And When to Call Us)

    November 2, 2025

    Keep Sensitive Data Private by Disabling AI Training Options

    November 2, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Samsung promises the Galaxy S26 with more AI, a custom chip, and new camera sensors

    October 30, 202514 Views

    Lab monkeys on the loose in Mississippi don’t have herpes, university says. But are they dangerous?

    October 30, 202513 Views

    Are you a YouTube TV subscriber looking for ESPN and ABC? Here are your options

    October 31, 202511 Views
    Don't Miss

    Access Denied

    November 2, 2025

    Access Denied You don’t have permission to access “http://www.edmunds.com/car-news/mercedes-benz-boulder-sprinter-debut-first-look.html” on this server. Reference #18.dc3f655f.1762063472.d41c82c https://errors.edgesuite.net/18.dc3f655f.1762063472.d41c82c

    don’t peel off that screen protector on the iQOO 15

    November 2, 2025

    Pay for Apple TV+ Annually to Avoid the Recent Monthly Price Increase

    November 2, 2025

    Trump’s swift demolition of East Wing may have launched asbestos plumes

    November 2, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    Samsung promises the Galaxy S26 with more AI, a custom chip, and new camera sensors

    October 30, 202514 Views

    Lab monkeys on the loose in Mississippi don’t have herpes, university says. But are they dangerous?

    October 30, 202513 Views

    Are you a YouTube TV subscriber looking for ESPN and ABC? Here are your options

    October 31, 202511 Views
    Our Picks

    Access Denied

    November 2, 2025

    don’t peel off that screen protector on the iQOO 15

    November 2, 2025

    Pay for Apple TV+ Annually to Avoid the Recent Monthly Price Increase

    November 2, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2025 Tolcome. Designed by Aim Digi Ltd.

    Type above and press Enter to search. Press Esc to cancel.