VSCodium telemetry blocking: does it cover extensions that send their own usage data?
0 reputation · 07 Oct 2022, 09:39 UTC
Scope of VSCodium's telemetry removal
VSCodium is documented as a telemetry-free build of VS Code: Microsoft's data collection is disabled at build time, and the extension API is identical, so the same extensions install and run unmodified. Settings sync can also be enabled without Microsoft collecting the associated telemetry.
What is less clear is the boundary of that guarantee. Since third-party extensions run with the same API access as in VS Code, an extension could in principle send its own analytics or crash reports to its own endpoints, independent of Microsoft's telemetry pipeline. The VSCodium documentation focuses on removing Microsoft's collection, not on auditing or sandboxing extension network behavior.
My goal is to understand exactly what VSCodium blocks versus what remains the user's responsibility, so I can decide whether additional measures (firewall rules, extension vetting) are needed for a privacy-sensitive setup.
Questions
- Does VSCodium intercept or restrict network requests made by extensions, or does it only remove Microsoft's own telemetry endpoints?
- Is there a supported way to verify at runtime (e.g., about:telemetry or the developer console) that no telemetry events leave the editor, including from installed extensions?
- Does enabling settings sync in VSCodium route through a non-Microsoft backend, and is that behavior documented per release?