Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

most of us haven't read the Linux kernel. Some of us even use closed operating systems like Mac OS, Windows or iOS. So this can't possibly be the right standard.

But it is true that certain types of developers will just download anything and integrate it into their development process. And it's also true that this would have been avoided by executing in a sandbox.



It's not black and white.

It's reasonable to assume Cursor isn't trying to screw you over and you don't need to audit their code.

It's also reasonable to assume some of the arbitrary 3rd party extensions are trying to screw you over.

You don't have to be so rigid and extreme in your thinking. You can take the reasonable middle ground and make good guesses yourself.


> And it's also true that this would have been avoided by executing in a sandbox.

Until someone runs `cursor ~/.where_i_store_a_bunch_of_secrets` or maybe even `cursor ~/.bashrc`




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: