Hacker News

Favorites Setup
Comment by 3eb7988a1663 | original | Mxc: Microsoft Execution Containers version 1.0.0
[−]3eb7988a1663 · 2026-10-10 Sat 17:44 UTC · link
Microsoft security is a bimodal. They might have exquisite delineation for network resources in Sharepoint or Azure but consumer applications are a joke.

Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.

[−]saltamimi · 2026-10-11 Sun 00:12 UTC · link
End users aren't expected to care about security and if they do, usually they are in an enterprise setting where it's taken care of automatically by enterprise settings.

Not to say it's good or bad, just not the target market.

[−]mey · 2026-10-11 Sun 01:05 UTC · link
End users should be expected to care about security. They should not be the only guard rail, but they are part of the defense in depth plan.

You do know about all those security training courses HR makes your take every year that you skip over?

[−]pjmlp · 2026-10-11 Sun 08:48 UTC · link
Unfortunately they are there for compliance, unless there is a strong IT in place, which then again, makes them hated by everyone else.
[−]3eb7988a1663 · 2026-10-11 Sun 01:27 UTC · link
VSCode is targeted at a step above the standard end user, but even there extensions are not sand-boxed and the Workspace Trust is a single toggle.
[−]rsalus · 2026-10-11 Sun 01:50 UTC · link
Don't even get me started on PowerBI...
[−]xienze · 2026-10-11 Sun 09:16 UTC · link
> Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.

Because years of experience has shown that even users who should know better (developers) get extreme permission fatigue. The demand end users make is "it should just know without me having to click 'approve' all the time." Well, that's tough. You're basically stuck between a rock (fine-grained permissions) and a hard place (don't make me deal with it).