3 ms·
FUD as usual. I am so sick of people waving around the security word. If you are scared of dealing with files on Linux, I suggest you throw your computer in the
by aumerle 3y ago
FUD as usual. I am so sick of people waving around the security word. If you are scared of dealing with files on Linux, I suggest you throw your computer in the garbage and retire to a mountain fastness with no electricity. If you have a specific criticism of the kitty protocol make it, otherwise spare us the vague FUD.
- amluto 3y agoYou connect your terminal to a program (pts, which may map to a sandbox or a remote SSH server you don’t trust or just a file you feed to cat). And it contains an escape sequence that causes your terminal to read and process ~/.ssh/id_rsa or /etc/shadow or /dev/sda or /proc/self/something or some other wildly inappropriate object. And your terminal opens and reads the file. My terminal does not live in a mountain fastness, and it’s not as exposed as a web browser, but it should at least try to make it safe to feed it untrustworthy input.
- aumerle 3y agoHeavens! Your terminal opens and reads a file. What a disaster. Still waiting for a concrete issue with the actual kitty graphics protocol. How is it unsafe to feed a terminal that supports the kitty graphics protocol untrusted input. One single solitary example would go a long way to prove you aren't just full of hot air.