@0xabad1dea@infosec.exchange Not entirely.
Think of this attack vector:
External program accepts a malicious folder into VS Code.
VS Code is launched
VS Code executes arbitrary commands
What admin viewing siem logs will think VS Code is performing bad things/has it blocked?
@nicd@masto.ahlcode.fi But users can "authenticate" a variety of digferent ways. https://anubis.techaro.lol/ runs complex data instructions to authenticate real traffic. I see it in use quite a bit.
@bagder@mastodon.social You need one that lists the number of conferences that have topics presenting curl related themes.
or
Websites that have a curl | bash script