Microsoft defends intrusive dialog in Visual Studio Code that asks if you really trust the code you've been working on
- Reference: 1625684111
- News link: https://www.theregister.co.uk/2021/07/07/visual_studio_code_workspace_trust/
- Source link:
The feature, introduced last month in version 1.57, was initially [1]described as "extra security against code execution when browsing unfamiliar source code."
Unfamiliar code in this context might include code the developer has just written. For example, create an empty folder, add a readme.txt (or even leave it empty), open the folder in VS Code, and the editor presents a scary dialog asking "Do you trust the authors of the files in this folder?" The options are either to "enable all features" or to "browse folder in restricted mode."
[2]
Visual Studio Code running in 'Restricted mode'
Restricted mode "tries to prevent automatic code execution by disabling or limiting the operation of several VS Code features: tasks, debugging, workspace settings, and extensions," [3]state the docs .
[4]According to Dias , VS Code "is capable of running code from the workspace on your behalf to provide a richer development experience," which exposes developers to risks such as "the npm module that steals your crypto wallet private keys."
[5]
Dias noted there are multiple ways in which VS Code and its extensions execute code, some of them automated, such as pre-launch tasks that build a project for debugging, and potentially could have "an extra task executing arbitrary code unrelated to the build."
[6]
[7]
Jupyter notebooks run code, as does ES Lint, a linting tool for JavaScript. Initially, Dias explained, the team introduced warnings before all such actions, but then felt that multiple prompts for different purposes were worse than a single prompt for the whole workspace. In VS Code, opening a folder is equivalent to opening a workspace.
[8]Developing for Windows 11: Like developing for Windows 10, but with rounded corners?
[9]Stop. Look... Install Linux? The Reg solves Microsoft's latest Windows teaser
[10]Microsoft: Try to break our first preview of 64-bit Visual Studio – go on, we dare you
[11]Microsoft loves Linux so much that packages.microsoft.com has fallen and can't get up
Dias acknowledged the ugliness of the dialog that "is pretty big and it keeps coming up for every new folder you open, unless you take action to configure it." However, he said that when the team tried "passive notification," or disabling trust until specifically enabled, "usage data showed a very low rate of granting trust through the passive notification. In user studies, we watched people spend all their time thinking they had broken something."
[12]
A large modal dialog pops up whenever VS Code opens a folder for the first time
Therefore the current design has one modal, intrusive dialog that, once passed, enables everything. There is even an option to "trust the authors of all files in the parent folder" so that the feature can in effect be disabled for an entire collection of projects. There is also an option in Settings – Security to disable the feature completely.
[13]
The consequences of not trusting a folder: many features do not work
The feature is problematic, as VS Code users were quick to observe. "I was very happy to figure out how to disable the new 'Workspace Trust' feature in #vscode … if I didn't trust the code it wouldn't be on my system," [14]said one . "It has all the subtlety of a GDPR cookie banner and the charm of clippy," [15]said another . "When you ask #microsoft to make #vscode secure this is the stuff they come up with. #VistaPrompt," was [16]another take .
Workspace Trust does have a use case: safely browsing suspect code. But the notion that all the source code on a developer's PC is suddenly untrusted by default is an odd one, and modal dialogs are a blunt instrument that developers may confirm simply in order to get on with their work. Modern JavaScript projects, for example, often have thousands of files, many buried under a directory called node_modules. It is not humanly possible to check each one, and a huge number of different authors may be involved. Asking the developer to declare that they trust those authors may not materially improve security.
A developer [17]commented to one of several GitHub issues seeking to improve or remove the feature by complaining that VS Code is "gradually sliding from sweet simplicity into a DevOps platform designed for users with no IT experience."
[18]
Workspace Trust is well intentioned but the feature seems out of step with the philosophy of an editor that is lightweight and does not get in the way.
That said, the feature is optional and perhaps achieves the goal of raising awareness of the risks "when you download code from the internet." Dias promised a number of fixes and improvements "coming in the 1.58 release based on your input." ®
Get our [19]Tech Resources
[1] https://code.visualstudio.com/updates/v1_57
[2] https://regmedia.co.uk/2021/07/07/vscode.jpg
[3] https://code.visualstudio.com/docs/editor/workspace-trust
[4] https://code.visualstudio.com/blogs/2021/07/06/workspace-trust
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YOYkAAcjyQpl5GMd5MpHSAAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOYkAAcjyQpl5GMd5MpHSAAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOYkAAcjyQpl5GMd5MpHSAAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2021/06/28/developing_for_windows_11/
[9] https://www.theregister.com/2021/06/24/windows_teaser/
[10] https://www.theregister.com/2021/06/18/vs_2022/
[11] https://www.theregister.com/2021/06/17/microsoft_packages_404/
[12] https://regmedia.co.uk/2021/07/07/trust.png
[13] https://regmedia.co.uk/2021/07/07/restricted.png
[14] https://twitter.com/VAggrippino/status/1405082940002996226
[15] https://twitter.com/kevins8/status/1404808413448531968
[16] https://twitter.com/_prbh/status/1403254042919374854
[17] https://github.com/microsoft/vscode/issues/126310#issuecomment-870768421
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOYkAAcjyQpl5GMd5MpHSAAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[19] https://whitepapers.theregister.com/
Re: It seems like a good idea
This is 100% a good feature, I avoid opening code I'm unsure about in IDEs so being able to put code in safe mode will be really handy.
The popup could be less annoying though.
Professional stareless box clicker
They just want to train people into clicking boxes without reading, as fast as possible.
Next version will show "Do you relinquish your soul to Microsoft?" or something more sinister like "Do you give us irrevocable license to do whatever we want with anything you write?"
Thanks to GDPR and Cookie Law I am well trained in clicking any popup windows to go away, I don't even notice them.
Trusting trust, again
Is this what you get when you trust VS Code or is there more? Is there any guarantee that VS Code is not inserting bad code in your projects when you make a build? Are your sure? Have you checked the entire chain of software to make sure? From bios to OS, from compiler to editor and more?
If not, you should read Ken Thompson's [1]Reflections on Trusting Trust . All these dialogs are treating symptoms. The problem is elsewhere and the complexity does not help. Maybe we should start at reducing the self-inflicted complexity and move forward from there.
[1] http://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf
Not that macOS is in any sense perfect …
… but for years it's supported a quarantine flag that gets attached to downloaded stuff, and to files generated from that stuff (unzipped archives, mounted disk images etc.). If you try to do something that could allow a quarantined item to do damage, you're asked if you want to allow the action. If you do, the flag is cleared, and you're not asked again for that item. It can be a pita, but I find it a lot less rebarbative than Clippy.
"Redmond, start your photocopiers."
Running lint causes the code to be executed?
Of course it does! This is the same company that happily extended email to be executable code instead of a simple messaging platform so spammers could pwn your computer, added "features" to the web browser so anonymous adverts on "trusted" websites could pwn your computer, and made it much easier to run everything as administrator (root) rather than encouraging least-privilege software to limit the damage their new standards caused.
The real question is, "Do you trust the authors of Visual Studio?"
Re: Running lint causes the code to be executed?
Couple things:
1) ESlint is an open source project that has nothing to do with Microsoft, people commonly call it from their node build scripts which can be kicked off from inside code, so if you want to know why a static analyzer runs code talk to them (I'll disappoint you by adding that there's probably a good reason)
2) Jupyter Notebooks also has nothing to do with MS, but with the right plugin to integrate them you can run arbitrary code from inside the notebook (by design)
3) I'm pretty certain that before you add plugins vscode can't execute any code at all, it's a text editor that becomes an IDE as you customize it
4) vscode and pretty much all of its plugins are open source so there's no issue of trust, feel free to audit it yourself
(edit love that the MS hater brigade is already out to downvote a post that consists of four easily verifiable facts lol)
Put a checksum checker...
...in your code with a result checksum for each library file being called. (As well as checksumming its own footprint). If checksum's match then you've made some effort to verify your external sources. However, if your external sources in turn call libraries outside of their domain (which is a risk being discussed a lot these days), then you can't guarantee trust. Many coders are oblivious of the fact that this could happen
If all libraries were to have checksum checking built into them in this way, then you could have some protection against root of heirarchy change. If this were a coding "standard" whereby you called a library only if it met the structural checksum standard, and that each library it called committed to doing the same, then security problems would start to decrease.
Re: Put a checksum checker...
Sorry Ken,
Your comment cannot be trusted, it did not include a checksum.
Re: Put a checksum checker...
The type of trust you're talking about here is different, where you want to check that a library you're calling into isn't altered at runtime. The type of trust the article is talking about is during development where a dev has obtained code and wants to open it locally, since there are many ways for code to execute out of your IDE you want to distinguish between code you trust and code you're looking at but don't trust to execute on your dev machine.
If you're curious though, checksums aren't robust enough to be the basis of your library trust system. The usually proposed and sometimes implemented solution to the problem you're discussing is to sign code cryptographically where you use a private key and the code/executable itself to make a digest which is appended to the package, then people can verify that the code is unchanged by using your public key and their copy of the package at any time. Googlable keyword is code signing.
File metadata
If you were to download code from the internet, it would have the URL in the file's metadata, wouldn't it... why not check that instead of if a filename exists...?
I'm going to be a horrible person and say that this sounds reasonable. The motives make sense, the implementation is mildly annoying but it's basically SUPPOSED to be, or it wouldn't work (as they demonstrated). I will complain about many Microsoft-related things, but this is not one of them.
I used to loathe MS
Now is fully hate it.
To be fair
Asking me if I trust the author of code I've written seems quite reasonable.Especially when I work on code I wrote 10 years ago and wonder "what cretin wrote this garbage?"
It seems like a good idea
but to many people have "that would never happen to me" mindset