The VSCode remote editing feature, unlike Emacs' Tramp, installs a full Node-based agent on remote systems with extensive filesystem and process control capabilities, raising security concerns for development and production environments, particularly when combined with LLM-powered code generation.
https://fly.io/blog/vscode-ssh-wtf/
via https://hnrss.org/newest?points=100, https://hnrss.org/newest?comments=100