Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ahem.

From the article: "But then, at the top of the description, I found this message greeting me: [...]"

It's this way on the linked extension's page as well: https://marketplace.visualstudio.com/items?itemName=seanmcbr...

I think that's fairly prominent place and the only explanation for installing this extension could be either that it's acceptable - for example if one's using MSVSC to edit Wikipedia articles or something like that - or negligence to read anything but the title (which can't be helped).

(Well, author could've put "[INSECURE!!!! WILL STEAL YOUR CODEZ!!!!1one]" in the title... but should he?)



Apparently asking people to read the descriptions of plugins they are installing is too much effort


Look at the package file: https://github.com/Microsoft/vscode-spell-check/blob/master/...

The description, which is the only part visible in the search interface, contains no mention that this uses a web service.

See this comment how it should be done correctly: https://news.ycombinator.com/item?id=11805189


Interestingly it's just had a version bump which makes the description a lot more obvious:

"Uses a web service to detect mistakes and suggest fixes - great for Markdown or any text file."

https://github.com/Microsoft/vscode-spell-check/commit/70847...




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: