{
  "video_id": "reddit_1tvftne",
  "channel_slug": "programming",
  "channel_handle": "r/programming",
  "title": "1-Click GitHub Token Stealing via a VSCode Bug",
  "url": "https://www.reddit.com/r/programming/comments/1tvftne/1click_github_token_stealing_via_a_vscode_bug/",
  "external_url": "https://blog.ammaraskar.com/github-token-stealing/",
  "upload_date": "20260603",
  "published_at": "2026-06-03T05:26:28+00:00",
  "transcript": "\n\n--- Top Comments ---\n\n\n[41 upvotes] I'm no web developer so I can't follow this in detail but I get the gist of it. \n\n\nWeb browsers are such a disaster.\n\n[39 upvotes] Microslop at it again. The token should never have been account-wide. You're doing gods work\n\n[37 upvotes] >To summarize the last time I interacted with [MSRC regarding reporting a VSCode bug](https://blog.ammaraskar.com/vscode-rce/#microsoft-security-and-vscode), it was a horrible experience where they silently fixed the bug I pointed out without any credit. They also marked it as not having any security impact.\n\nMore public exposure to those PM and PO who don't understand software, because some manager that they report doesn't what bad press about security or those security bugs are reflecting really bad on his promotion\n\nIt took more than 2 decades for hackers to understand consequences of their curiosity and companies to benefit from their curiosity, so most of those hackers are happy to make a career out of it  \n  \nThe relationship can be beneficial for both parties as long as there is a respect and we currently seeing that Microsoft is trying to destroy all the goodwill  \nand this is the best response - transparency, so that Microsoft managers understand what it is at stake\n\nBecause there are always bad actors who are willing to take the opportunity and make damage ",
  "transcript_chars": 1359,
  "ingested_at": "2026-06-03T13:30:20.308901+00:00",
  "source": "reddit",
  "yt_meta": {
    "score": 258,
    "upvote_ratio": 0.98,
    "num_comments": 26,
    "author": "nicovank13",
    "is_self": false
  }
}