17 ms·
Material Theme has been pulled from VS Code's marketplace
- mock-possum 2y agoAnother creator gone off the deep end apparently? > reading the review responses by the creator, I don't really trust it anymore. Being rude to others who are concerned over the recent move to closed-source (and without warning!) is pretty disheartening. > So, uh, the guy who made the VS Code Material Theme is threatening everyone who uses it in their products. He seems to have forgotten it was originally licensed under the Apache License, 2.0.. He wiped the commit history to make it look like it was always his weird fake license. Real messy. It’s always shocking to me how little people realize - or care - how their behavior - especially their treatment of others reflects on them.
- tag2103 2y agoQuestion bouncing around in my mind reading this, especially with money involved, is why did this not cross the line into criminal fraud?
- joshka 2y agoBecause noone has stated an injury and made a complaint about it. It's likely that there's some copyright infringement going on with the current state of the repo (due to lack of the author's adherence to the requirements of the license). That could be subject to a DMCA notice if any of the previous contributors decided to make one.
- gosub100 2y agoConspiracy would be more appropriate, no? Thing is, when you conspire to attack a corporation, you have FBI agents bending over backwards for you and your precious profits. When you conspire to attack a bunch or normal people, you're lucky if anyone does anything at all.
- ryandrake 2y agoSo many people who are otherwise functional in society, for whatever reason just can't play well with others when it comes to online communication. This can be true for both software maintainers and users. People can't just leave their emotions at the door and file a bug report or respond to a help request, without including a little personal jab or passive aggressive snipe. Looking at some of those replies to users, it looks like this guy just couldn't keep himself from including those unnecessary little put downs.
- tuesdaynight 2y agoPeople say that the most part of communication is nonverbal. If that's true, written communication would be heavily impaired by the lacking of all the visual cues that we use to interpret someone's words. I tend to agree with them, but that's just my personal experience.
- kstrauser 2y agoWritten text is perfectly capable of communicating all that, as evidenced by zillions of poems, novels, essays, screenplays, etc. No, I counter that the real problem is that some people are either incredibly bad at communicating their real intent, or incredibly good at communicating their inner asshole nature.
- JTyQZSnP3cQGa8B 2y agoIt’s off topic but I don’t believe most people are functional in society. I think they are hiding their shitty behavior to themselves and to others, and their true self comes out once in a while. They hide it mostly to their family, but other human beings are treated like NPCs. For example I live in the south of France and people are literally crazy on the road but they still avoid accidents by some kind of miracle. These are people from all sex, color, and age. The good middle-aged white father becomes a fucking moron when his car is turned on. The young new mom who pretends to love her children is speeding on the road like an idiot. Society accepts that or turns its head the other way not to look at it, but it’s definitely around us and I see it every time I go to work.
- badrequest 2y agoIt seems utterly absurd to me that anybody should be able to issue a copyright claim on a collection of colors and fonts. Copyrights are issued to logos and slogans, not design systems.
- lelandfe 2y agoIf you think that sucks, check out T Mobile trademarking magenta https://www.npr.org/2019/11/25/782723429/t-mobiles-parent-tells-small-firm-to-keep-its-hands-off-magenta https://www.npr.org/2019/11/25/782723429/t-mobiles-parent-te...
- scubadude 2y agoCadbury and purple... These colours are their trademarks but I believe they don't own the colour in all domains.. probably just food? If you wanted to make a car company logo that colour you'd be ok?
- spudlyo 2y agoIt seems utterly absurd to me we litigate the ownership of ideas or their expressions, but here we are. The founder of Bikram Yoga, tried to copyright a sequence of yoga poses, even though similar sequences have existed for for thousands of years. Monster, the energy drink maker, went after business for using the word "monster" in totally unrelated contexts. Disney trademarked "Hakuna Matata" (a Swahili phrase roughly equivalent to "no worries") after using it in The Lion King, prohibiting African businesses from using a common idiom in their own damn language. Don't get me started on Happy Fucking Birthday.
- School-Cotton 2y agoNo, trademarks are issued to logos and slogans.
- kelnos 2y agoYes, but many logos are also copyrightable.
- xeonmc 2y agoThe old commit history can still be accessed here: https://github.com/material-theme/vsc-material-theme/activity https://github.com/material-theme/vsc-material-theme/activit...
- joshka 2y agoThis doesn't capture all of it though. There's also a bunch more that you can access by looking at commits in the Pull Requests.
- xeonmc 2y agoIt does, you just needs to find the last one before force push and click “browse repository at this point” and it will slow the pre force push history
- joshka 2y agoFeel free to check for yourself, but the commits where the repo is licensed as MIT are not reachable from that UI - only the commits where the repo is licensed as Apache 2.0 (and the later self- created license). The earliest available activity entry is from 2023, which bottoms out at an initial commit from 2017. The code base is actually older than that having been started in 2015. The commits which have the real unadulterated history of the theme are available by taking the same actions on the PRs (browse repo), as they point at commits in other repos where that history has not been erased not the main repo where it has. I suspect this probably indicates that the GitHub repo was recreated in 2023 with a modified version of the source with the Apache license and a history that was rewritten to not contain the commits where the license was MIT. This aligns with what people are saying about the historical perspective on this.
- joshka 2y agohttps://github.com/material-theme/vsc-material-theme/commit/e98b4029ee5d09f5261fa1961cb0e3129a7eb8cf https://github.com/material-theme/vsc-material-theme/commit/... is the initial MIT licensed commit
- gedy 2y agoWhile I appreciate he put in a lot of work (thank you for the theme) - Material Design is someone else's work as well..
- nonethewiser 2y agoHe also seemed to put a lot of work into the license he wrote and updated many times.
- deadbabe 2y ago[flagged]
- ruined 2y agogit is a blockchain
- School-Cotton 2y agoNo it’s not. A blockchain is a Merkle tree whose canonical “master branch” is agreed upon by everyone and difficult or impossible to change (e.g. due to PoW or a similar mechanism). A git repository is just a Merkle tree.
- ruined 2y agoa similar mechanism, like... a consensus mechanism? public key cryptography? some kind of content-based addressing? social convention and agreement on which fork to use? is it easy for you to go edit historical commits in the linux repo?
- notpushkin 2y agoA Git repository is a Merkle tree whose canonical “master branch” is agreed upon by everyone and difficult or impossible to change (because people want to collaborate on a project). If you try to rewrite history and people don’t agree with you, they would just fork the project and get on with their day.
- deadbabe 2y agoLet me clarify: a global blockchain.
- compootr 2y agoReading the commentary, this guy seems unhinged. He thinks he owns literal hex codes he sucks at tech and has driven away everyone good at it. I don't use his software, but I hope he gets out of this episode soon (and learns he didn't invent material!)
- ukuina 2y ago> He thinks he owns literal hex codes Pantone would like a word.
- donatj 2y agoPantone is a lot more than hex codes, it's a whole system of material science for colors.
- Krutonium 2y agoYep - Give them a Pantone Color and a Material, and they can tell you how to get that material in that exact color.
- Waterluvian 2y agoI dunno. I asked for the Pantone of neon brown on transparent aluminum and they stopped returning my calls.
- moralestapia 2y agoYou should do stand-up comedy.
- joquarky 2y agoNeon brown is orange :)
- Dylan16807 2y agoPantone does a lot of legitimate work, but also they pretend to own the hex codes for their colors.
- firesteelrain 2y agoSo weird that this person took contributions from others then made it closed source. It doesn’t seem right, but not a copyright expert.
- KennyBlanken 2y agoWas Material even his work in the first place?
- mook 2y agoLooks like it was, or at least the initial commit was. This was back in 2017. https://github.com/material-theme/vsc-material-theme/commits/?after=0c9892823accd22589695f04af2fc25dd6f3a137+1020 https://github.com/material-theme/vsc-material-theme/commits... I'm not sure why the initial commit already says "official", but that's almost a decade ago.
- joshka 2y agoThe initial commit was in 2015 and was MIT licensed for a couple of years before it was changed to Apache licensed. It's unclear if any of the other contributors gave permission for this change to happen. https://github.com/material-theme/vsc-material-theme/commit/e98b4029ee5d09f5261fa1961cb0e3129a7eb8cf https://github.com/material-theme/vsc-material-theme/commit/...
- schneems 2y agoSpeaking generally: It’s assumed that your contribution will be licensed with the current license (generally). Maintainers can change the license but that wouldn’t affect prior contributions. Basically anything up to that license change would still have the original license. This is what makes forks possible when popular software changes their license. In order to go back in history and change a license, you need either the consent of your contributors or a document that would grant you the power to do that. A CLA could (but not all CLAs will) grant a maintainer to change a license at will back in time. Other famous software that has seen a license change: Redis and Terraform. In those cases the license changed but already released software is still available with the old license and that old license allows for forks.
- Starlevel004 2y agoWhat is it about material themes that does this to people? The same kind of thing happened to the IntelliJ one half a decade back. At least that one wasn't literally just colours.
- do_not_redeem 2y agoSomeone uploaded a replacement, Material Theme (But I Won't Sue You) https://marketplace.visualstudio.com/items?itemName=t3dotgg.vsc-material-theme-but-i-wont-sue-you https://marketplace.visualstudio.com/items?itemName=t3dotgg....
- oefrha 2y agoThe original author seemed to talk a lot about funding development/maintenance, so I got curious about what the hell needs to be maintained. I cloned the https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you repo and had a look. Here's a LoC summary: =============================================================================== Language Files Lines Code Comments Blanks =============================================================================== CSS 2 142 119 0 23 TypeScript 32 2026 1650 243 133 ------------------------------------------------------------------------------- HTML 2 59 49 1 9 |- JavaScript 2 2 2 0 0 (Total) 61 51 1 9 =============================================================================== Total 36 2227 1818 244 165 =============================================================================== Among those, 622 lines of TS are hex color definitions for variants in scripts/generator/settings/specific. Most of the rest seems pretty boilerplatey, e.g. look at the 599 lines in scripts/generator/color-set.ts. So the question remains: what the hell is there to maintain (that takes more than a couple minutes every $godknowshowlong)? I've published and maintained waaaaay more substantial open source projects for years without expectation of any financial contribution.
- bad_user 2y agoThere's nothing wrong with building proprietary software of a couple of thousand lines of code, including themes. And people should be able to ask for money in exchange for their work. What's wrong is the bait and switch, as these projects end up being popular because of their FOSS nature.
- bravetraveler 2y agoThe day {n,}vim take away my color schemes, I die. Convenience until it isn't, eh?
- iLemming 2y agoYeah well, MSFT - the behemoth among evilish corporations, invests vast sums into developing a sophisticated tool with extensive features - more than their combined philanthropic initiatives - and offers it freely to just about anyone. This generosity doesn't seem questionable at all, eh? I mean, when I use Vim and Emacs, the benefits clearly flow to users and the developer community. Back when I paid for the IntelliJ license - I knew exactly how their revenue model worked. Yet whenever I download and use VSCode, I don't really know what's Microsoft's grand plan here, does anyone else do?
- bravetraveler 2y agoMicrosoft <3 Open Source /s
- not_a_bot_4sho 2y agoCommunity goodwill is valuable. It's what gets someone to start to think, "this is pretty good, maybe I should try that Azure thing..." Same reason Xcode is free.
- deleted 2y ago[deleted]
- koakuma-chan 2y agoNobody is gonna pay for a VSCode theme.
- vorpalhex 2y agoI'd pay off the cuff money ($5) if it wasn't paywalled. "Donationware" if you will. I do this with other apps/resources/things including a nice pixel font I like using in images. I suck at colors and want nice themes. I'm glad people better at this than me take time to make nice things. But, I don't want to ever manage licenses for my theme. My dotfiles need to fetch it automatically or it's out.
- weinzierl 2y agoPeople pay for mere color schemes. https://draculatheme.com/ https://draculatheme.com/
- koakuma-chan 2y agohe's even selling a book lmao
- johnisgood 2y agoAnd shirts, hoodies, hats, etc. Wild. :D I am more curious as to why one would buy the theme and related merch.
- dr_kiszonka 2y agoOver $390k in sales! https://draculatheme.com/open https://draculatheme.com/open
- pinoy420 2y ago[dead]
- NetOpWibby 2y agoI paid for Dracula back when I could stare at dark mode for hours. Now I use Monokai Pro Light (paid for this too). Free themes are a dime a dozen. Paid themes means someone's incentivized to keep working on it and adding icons, &c.
- joshka 2y agoIf you do a bit of a repo dive, the repo was initially MIT licensed from its initial commit for at least a couple of years before that license was replaced by Apache 2.0, so there's an argument to be made that that license also applies.
- sparkie 2y agoThe Apache or MIT license would permit you to continue using it for all versions up to the last commit which used that license. Any later commits under a different license would not be Apache licensed and you would need to follow the new terms if using those newer versions. The new license doesn't prevent you from sharing forks of the older version which was Apache/MIT licensed.
- joshka 2y agoKinda, it's complicated. When someone other than the owner of the repo contributes code, they own the copyright to that code. When the author changes this repo's license like this they're redistributing the external contributor's copyrighted code. The permission to do so is granted by the Apache 2.0 license and is subject to the conditions of it. Without the permission to distribute the contributed code, the author is engaged in a violation of copyright law. Note the Apache terms: > "You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License. This covers not just the users, but also the "author" here who exercises the permissions granted below: > 2. Grant of Copyright License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form. > 4. Redistribution. You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions: > (a) You must give any other recipients of the Work or Derivative Works a copy of this License; and So let's interpret that. Regardless of the whatever intent to re-license the code exists in the mind of the author, in order to distribute the code which was contributed by others, the only legal means to distribute this code must comply with the requirements of the license. Technically they could remove all code contributions which were contributed by others (I've done this in the past, it's a pain to do right), or seek permission from the others to add additional grants that are not included in the Apache license here (I've seen various projects do the post-facto CLA thing for this). But that has not happened here. So (in my opinion) the github repo of the author is a currently infringing the copyright of all the other contributors. Any one of whom could enforce it or raise a DMCA take down notification on the repo. So given that we're talking about material that is in breach of copyright, it's likely that being able to enforce a license on that as a consumer is not really a thing which is possible as the conditions on what must be included bind the person distributing the material not the person receiving it.
- pinoy420 2y ago[dead]
- ahoef 2y agoDiscussion has been deleted. Edit: the whole repo has been put to private.
- nguyenkien 2y agoHe rename it: https://github.com/Fanny-Theme/fanny-theme-support https://github.com/Fanny-Theme/fanny-theme-support
- deleted 2y ago[deleted]
- Dylan16807 2y agohttps://web.archive.org/web/20250226020241/https://github.com/material-theme/vsc-material-theme/discussions/1313 https://web.archive.org/web/20250226020241/https://github.co...
- StrauXX 2y agoThe post has been deleted: https://web.archive.org/web/20250226020241/https://github.com/material-theme/vsc-material-theme/discussions/1313 https://web.archive.org/web/20250226020241/https://github.co...
- isidorn 2y agoHi - Isidor here from the VS Code team. A member of the community did a deep security analysis of the extension and found multiple red flags that indicate malicious intent and reported this to us. Our security researchers at Microsoft confirmed this claims and found additional suspicious code. We banned the publisher from the VS Marketplace and removed all of their extensions and uninstalled from all VS Code instances that have this extension running. For clarity - the removal had nothing to do about copyright/licenses, only about potential malicious intent. Expect an announcement here with more details soon https://github.com/microsoft/vsmarketplace/ https://github.com/microsoft/vsmarketplace/ As a reminder, the VS Marketplace continuously invests in security. And more about extension runtime trust can be found in this article https://code.visualstudio.com/docs/editor/extension-runtime-security https://code.visualstudio.com/docs/editor/extension-runtime-... Thank you!
- joshka 2y agoCan you please clarify whether the fork also suffers from the same security issues (or engage the fork's owner to ensure that it doesn't https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you)
- isidorn 2y agoThanks for flagging it. Our security researchers will analize it and based on their findings we might remove this one as well.
- csears 2y agos/analize/analyze/g
- theo-steiner 2y agos/g/
- theobr 2y ago
- KronisLV 2y agoI'm quite happy that nowadays most tools have competently made themes out of the box, so that if someone wants to minimize risks from something like this and keep the extensions/addons they install to a minimum, that's pretty viable. Of course, it's also nice that it's possible to theme the software to such a degree and improve usability and accessibility in some cases, just that the feature requests about limiting permissions need to be addressed.
- oneeyedpigeon 2y agoI find it curious that themes can be a security risk at all. Clearly, they consist of more than just the colour codes and don't definitions one might assume. Maybe the theming system needs to be tightened.
- theobr 2y agoHey y'all, I made the most prominent fork of this extension "Material Theme (But I Won't Sue You)" The maintainer went off the deep end last year. He pulled the (originally apache 2) source offline, then started threatening to sue people for hosting alternative versions, including them in other IDEs, etc. Genuine lunatic. Out of an abundance of precaution, I've taken the following action on my fork: 1. I have the VS Code team auditing it as we speak, and I've given them full permission to immediately pull it from the marketplace & force uninstall it from users if they find ANYTHING malicious. 2. I have audited the code base thoroughly (nothing seemed malicious) 3. I have removed ALL code related to changelogs, analytics, Open Collective and html rendering. The only thing that seemed slightly concerning was the html + sanity loader for changelogs, so I gutted it entirely. Two PRs removed almost all the deps and over 7,000loc (mostly package-lock) Repo is here if anyone else would like to audit https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you https://github.com/t3dotgg/vsc-material-but-i-wont-sue-you
- ukFxqnLa2sBSBf6 2y ago[flagged]
- Apfel 2y agoHe's being as helpful as possible, there's no need to go hard on his language like this.
- ukFxqnLa2sBSBf6 2y agoI don’t think went that hard though? I was just pointing out the discrepancy between what they said and what they mean. Not everyone might know that the marketplace doesn’t need you permission to remove your extensions.
- WithinReason 2y agoI don't think they need his cooperation either
- oneeyedpigeon 2y ago
- joshka 2y ago@dang can you please update the link to the archive link
- throw16180339 2y agoHN doesn't have callouts. If you want dang to see your comment, email hn@ycombinator.com.
- dang 2y agoUsually it's better to put an archive link in the comments, not at the top, so the original domain isn't obscured. I've pinned the archive link to the top now (and detached this subthread from https://news.ycombinator.com/item?id=43181471 https://news.ycombinator.com/item?id=43181471). (As throw16180339 said, please email hn@ycombinator.com with these things - that's the only way to be (mostly) sure I'll see it.)
- globular-toast 2y ago100s of people disrupted because Microsoft remotely changed the colours in their editor? Come on, people, you need to own your own tools.
- bunbun69 2y ago> 100s Source? > disrupted Source?
- GlacierFox 2y agoWhat even is this comment? The extension has been deemed to have malicious code in it so it's been pulled. It's been remotely removed from users who have signed in to Code and I'm thankful for that. Should I be furious?
- TZubiri 2y agoOne of the things I love about the internet is learning how different people can be, I perceive it as different than me but I assume everyone has their quirks. In this case, this is one of the most extreme instances of people installing lots of dependencies. The moment I realized something was different in me was left pad, I already felt that couldn't be me. The log4j incident hit me different, it COULD have easily been me. A security vulnerability is like death or a terminal illness in my eyes. Successful companies that scale do so without incidents, If you are running a company and you have a vuln you are out of the race. So I tightened up a lot after that. I realize something similar with sex I just can't fathom putting my whole life on the line just to have sex with somebody and then have nothing to show for it, no relationship, nothing. And today we see this, people are really risking their companies, their reputation, their pride to have pretty colors on their IDE. I used to fight it, try to convince people, of course I still keep the pride of being different and weary, but in the end, you will likely be fine, and I only hold a statistical advantage, both are valid strategies of going about life I guess.
- wizzwizz4 2y ago> The log4j incident hit me different, it COULD have easily been me. That couldn't be me, because I don't use Java, PHP, Windows APIs, or `xdg-open`. The closest I come to Java-esque "include ALL THE BATTERIES" is the occasional Python script, but I won't use `http.server`. (Incidentally, I don't get very much done.)
- TZubiri 2y ago> (Incidentally, I don't get very much done.) Lol, that's definitely part of the tradeoff of security in life. > I don't use Java I didn't use Java either, but whatever I was using at the moment (Python) could have been anything, if I stayed in my other job or gotten a different one I could very well been using Java and been the one that installed the thing. >Python script, but I won't use `http.server`. (Incidentally, I don't get very much done.) Interesting, I use http.server or the Tcp socket server thing, but I consider myself to be in the extreme, there's still people that use Flask (and I do partake ocasionally) or things like Django, Spring, Next,etc... Same with binaries like Apache, Nginx. I mean you gotta use something, and if you go too far on the deep end, you get the risk of introducing the vulnerabilities yourself, (in addition to the risk of getting nothing done as you mentioned). I know my limits I wouldn't implement cryptography for example.
- Alifatisk 2y agoCan anyone help point out where in the repo the malicious part was? Can't find it. Found the obfuscated code here https://web.archive.org/web/20250226020241/https://github.com/material-theme/vsc-material-theme/discussions/1313 https://web.archive.org/web/20250226020241/https://github.co...
- Eikon 2y agohttps://archive.is/SFH7m https://archive.is/SFH7m
- GlacierFox 2y agoLooks like he's responded to it here. Delusional maniac? (Also, don't download and install that file he links) https://github.com/material-theme/vsc-material-theme/discussions/1314 https://github.com/material-theme/vsc-material-theme/discuss...
- Alifatisk 2y agoIs there any archive to that discussion? It's now deleted and couldn't find it on archive.is
- Retr0id 2y agoI downloaded it to take a look, all the js is obfuscated via https://github.com/javascript-obfuscator/javascript-obfuscator https://github.com/javascript-obfuscator/javascript-obfuscat...
- lil-dev 2y agoIn VS Code linux is very annoying the message that appears as a notification "We have uninstalled..." I try to remove the extension and after a few seconds it appears again and again. I think I have to use another IDE for today, fix this guys. PLS
- wlonkly 2y agoIt might be Settings Sync trying to restore it?
- lil-dev 2y agoit is very annoying the message that appears in VS Code linux, "We have uninstalled 'equinusocio..." please guys fix this. I have tried to uninstall the extension but magically it appears again, for today I have to use another IDE because of how annoying it is...
- valsaven 2y agoI did the following (it might help you too): 1. Close VS Code 2. Go to `C:\Users\USER\.vscode\extensions` 3. Delete the folder with that extension 4. Open extensions.json, find and delete the block related to that extension, then save the file 5. That’s it
- kirillragozin 2y agoCan confirm this works :)
- dev1ycan 2y agoOh no... anyways. I use dark high contrast... guaranteed to work on any IDE (and) you don't get this.
- thih9 2y agoThis HN submission now links to a 404 on github. Is the original source code still uploaded somewhere?
- jackmhny 2y agohttps://archive.is/SFH7m https://archive.is/SFH7m
- manuelmoreale 2y agoI think the guy simply renamed and moved everything here? https://github.com/Fanny-Theme/fanny-theme-support https://github.com/Fanny-Theme/fanny-theme-support
- meerita 2y agoI got a message today saying the theme has malicious content and it was removed from my VS Code.
- sigmoid10 2y agoCuriously, someone on reddit noticed suspicious changes in this extension 7 months ago [1]. Obfuscation in open source is usually an extreme red flag. Microsoft really needs to rethink their security model for vs code extensions. It has simply become way too profitable to target given whatever they are doing against it. For every dev they ban 10 will come with new malicious extensions. [1] https://www.reddit.com/r/vscode/comments/1eq40o2/has_the_material_theme_extension_been_compromised/ https://www.reddit.com/r/vscode/comments/1eq40o2/has_the_mat...
- bun_at_work 2y agoBe careful what you wish for. VS Code is maybe the best product Microsoft has ever released, largely because the extension market. If Microsoft polices the marketplace more, you can probably expect VS Code quality to degrade. Here's my argument: More scrutiny of the marketplace will lead to less extensions overall (the scrutiny process will reduce the number of extensions overall as barrier to entry will be increased). Less extensions available will create an incentive for Microsoft to add features to VS Code directly. The more features MS adds, the more bloated VS Code will become. So then, more security auditing in the extensions marketplace will lead to a more bloated VS Code. All that said, it would be nice if there were better security controls in the extensions marketplace, I just don't trust Microsoft to do anything in a way that actually improves their products for the people who use them.
- deleted 2y ago[deleted]
- homebrewer 2y agoYou do not have to police everything, copy what Mozilla is doing: pass the top X extensions through manual audits (including looking at code diffs on every update) and mark them as trusted. Maybe also add a giant warning "this extension may steal your stuff" when installing everything else.
- sigmoid10 2y agoIt took a while, but Microsoft got it pretty much right with Windows Defender. It quietly made all other active scanners obsolete. It's just a question of how much effort they're willing to spend on a free product's infrastructure.
- hemant1041 2y agoRip.
- TaurenHunter 2y agoThis appears to be the original source code, before the change to the license and suspicious code: https://github.com/Dramaga11/vsc-material-theme https://github.com/Dramaga11/vsc-material-theme
- MortyWaves 2y agoTheo of internet drama fame interjecting himself into the middle of it as always.
- chroma 2y agoCould you elaborate? I have no idea who “Theo of internet drama fame” is.
- deleted 2y ago[deleted]
- MortyWaves 2y agoEssentially an internet personality. While they sometimes make interesting points, mostly on X, Twitch, and YouTube, he often seems to interject himself into a lot of things needlessly. Before this Material thing, it was that Wordpress incident.
- MortyWaves 2y agoHere’s some more insight https://x.com/1mortrix/status/1897389705005879461?s=46 https://x.com/1mortrix/status/1897389705005879461?s=46
- itorcs 2y agoIf the size of your paycheck depends on drama and making a surprised look in a YouTube thumbnail you would possibly insert yourself into the middle of things also
- makizar 2y agoAha, he's way ahead of you: https://www.youtube.com/watch?v=3wz7YF2as-c https://www.youtube.com/watch?v=3wz7YF2as-c
- tempaccount420 2y agoThis whole thing makes him look like a vulture. Just let the theme die or let someone make a better one from scratch. The reason he forked it in the first place is, as he said himself, because he's famous.
- mannotcool 2y agoI found the malicious javascript (messages.js) file and put it in a Pastebin for anyone to analyze https://pastebin.com/yY1X0LiD https://pastebin.com/yY1X0LiD obviously its obfuscated by the guy originally
- kevlened 2y agoThis code is harmless. We may need a copy of the actual, shipped extension from vscode. https://pastebin.com/T998ZstM https://pastebin.com/T998ZstM
- flutas 2y agoHere's a copy of it to download directly from MS... I've seen literally nothing malicious in it so far. !!! WARNING CLAIMED MALICIOUS PACKAGE !!! https://marketplace.visualstudio.com/_apis/public/gallery/publishers/Equinusocio/vsextensions/vsc-material-theme/34.7.9/vspackage https://marketplace.visualstudio.com/_apis/public/gallery/pu...
- codeptualize 2y agoIsn't it about release-notes.js? There are quite a few files in there that are obfuscated. So far I haven't found anything super bad, it looks like a sanity.io client of some sorts, but there could be some stuff hidden in there as it's seems like quite a big JS bundle.
- hassleblad23 2y agoNoo.. please bring it back.
- Vincenc 2y ago[dead]
- lifeplusplus 2y agoMaybe there should be pool fund. Say you contribute $20 a year to it, and it gets distributed to all extensions you have monthly
- rmac 2y agothe "we took this down for security" is such a tempting _acceptable_ form of censorship. My bank does this for my suspicious transactions, with a near %100 false positive rate.
- Capricorn2481 2y agoYou're saying your bank is censoring something you do when it flags a transaction? For me it's just flagging big purchases I don't normally make. Seems common sense and usually remedied by a text to a bot.
- pro123321 2y agoanybody knows how to remove that pop up?
- pro123321 2y agohow to remove that pop up which keeps coming?
- jpb0104 2y agoAre these the same developers? https://plugins.jetbrains.com/plugin/8006-material-theme-ui https://plugins.jetbrains.com/plugin/8006-material-theme-ui
- Brainspackle 2y agoI am wondering this too! EDIT: Did some research and looks like it is different code by different developers, so we should be good.
- jpb0104 2y agoThanks for digging in.
- prmoustache 2y agoWhy would a theme contain code in the first place. Shouldn't it just be made of static value containing color codes?
- 7373737373 2y agoWhy would any add-on have more authority than it needs? Oh right - because no currently popular language supports implementing that kind of resource/rights monitoring and control: https://medium.com/agoric/pola-would-have-prevented-the-event-stream-incident-45653ecbda99 https://medium.com/agoric/pola-would-have-prevented-the-even... An absolute failure of contemporary programming language design. Software firms need to think harder about what kind of guarantees the languages they use can give them - which part of a project's code can access which (and how many) resources - access to other project components, filesystems, the network, and the amount of process memory and CPU time they are allowed to consume. The current default answer is usually "any place has authority to access everything else, and a simple infinite loop will use up all the system's resources"
- user99999999 2y ago“Can’t wait to see the Netflix documentary about this”
- wbakst 2y agooriginal link here is now broken
- Random12314 2y ago[dead]
- bstsb 2y agofrom a quick deobfuscation of some of the code, i can't see anything wrong with it? i think this is just a case of obfuscated code being against the VS Code guidelines. the guy clearly wanted people to buy his pro version so maybe that's why he obfuscated all the code in the extension
- withinrafael 2y agoIt appears Microsoft released their 'detailed announcement' - it's just a one-sentence fragment in a Markdown file: https://github.com/microsoft/vsmarketplace/blob/main/RemovedPackages.md https://github.com/microsoft/vsmarketplace/blob/main/Removed... I'm increasingly suspecting there was nothing actually wrong with the extension, and Theo and others may have simply demolished an open-source developer's reputation primarily because they found him difficult to collaborate with. This is nuts.
- deleted 2y ago[deleted]
- Mike_Andreuzza 2y ago[dead]