4 ms·
Ah so classic FUD, "its unknown what it can do". Why dont you spend some effort figuring out what it can actually do instead of making driveby comments with an
by aumerle 4y ago
Ah so classic FUD, "its unknown what it can do". Why dont you spend some effort figuring out what it can actually do instead of making driveby comments with an obvious axe to grind.
You very conveniently left out the fact that pretty much anything that views untrusted content has to parse files. If parsing files is where your "security boundaries" lie, I suggest you drop your computer off at the garbage dump. Hell if your editor has a preview function it too will parse untrusted content. Basically, to do anything software has to parse untrusted content. And just by the way, /etc/passwd is not attacker controlled. If the attacker has access to your filesystem already, she really doesnt need to use kitty to do anything. And "opening" README.md will not cause kitty to parse files, unless by "opening" you mean catting without -v. In which case we are back to your mommy told you to know better but you didn't listen.
At this point its obvious you are deliberately trying to spread FUD. I am done interacting with you. Good bye.
- yencabulator 4y agoBecause security is hard nobody should even try? The general trick with parsing is to put it in a sandbox that cannot touch files, can only do limited syscalls, etc. This is what e.g. Chrome does. But yes, it's obvious the Kitty author has no interest in making it more secure ( https://github.com/kovidgoyal/kitty/issues/2084 https://github.com/kovidgoyal/kitty/issues/2084) and it's obviously you take discussions about improving software security as attacks on your person. Have a good day, sir.
- aumerle 4y agoOh man, this is rich :))) Let me just leave this for posterity. kitty has had a socket for remote control for years: https://sw.kovidgoyal.net/kitty/conf/#opt-kitty.allow_remote_control https://sw.kovidgoyal.net/kitty/conf/#opt-kitty.allow_remote... (see socket-only). It can allow remote control from specific windows while disallowing it generally: https://sw.kovidgoyal.net/kitty/launch/#cmdoption-launch-allow-remote-control https://sw.kovidgoyal.net/kitty/launch/#cmdoption-launch-all... Furthermore the next release of kitty has capability based security for remote control with public key crypto to keep the data safe: https://github.com/kovidgoyal/kitty/discussions/5320 https://github.com/kovidgoyal/kitty/discussions/5320 I suggest you find a better place to move the goalposts in your attempts to smear and spread FUD.