3 ms·
It is not enabled by default? You need to log in with a GitHub or Microsoft account, install the remote dev extension, and then explicitly enable the feature on
by Longhanks 3y ago
It is not enabled by default? You need to log in with a GitHub or Microsoft account, install the remote dev extension, and then explicitly enable the feature on a per-machine basis (and yes, this can be done via the CLI, as the article mentions).
If you don’t know the feature set of the software you use, maybe don’t use the software instead of blaming the vendor.
- CalChris 3y agoBut I don't want to know this feature in order to use this editor. Apparently Auto Closing Overtype deserves an enable/disable/auto flag but Embedded Reverse Shell doesn't. Yo Microsoft, add a preference for this thing which defaults off.
- oefrha 3y ago1. You don’t need to install any extension, `code tunnel` is builtin, the extension is UI stuff using the tunnel. No need for any extension to open a reverse shell. 2. It’s about an attacker exploiting the feature, the attacker is enabling it and doing the login. Whether you need to enable it yourself is largely irrelevant, in fact you’re probably more likely to notice an ongoing attack if you use the feature yourself. Anyway, default is pointless, a gadget is a gadget as long as the bits are there and easily executable.
- ethbr1 3y ago> If you don’t know the feature set of the software you use, maybe don’t use the software instead of blaming the vendor. Saying this in reference to modern Microsoft, with their default-opt-in-to-drive-market-share strategy, is a pretty high bar. Effectively it means "Don't use Windows."