Comment by saltamimi

2 hours ago

End users aren't expected to care about security and if they do, usually they are in an enterprise setting where it's taken care of automatically by enterprise settings.

Not to say it's good or bad, just not the target market.

VSCode is targeted at a step above the standard end user, but even there extensions are not sand-boxed and the Workspace Trust is a single toggle.

End users should be expected to care about security. They should not be the only guard rail, but they are part of the defense in depth plan.

You do know about all those security training courses HR makes your take every year that you skip over?