10 ms·
Déjà vu: Ghostly CVEs in my terminal title
- sevg 2y agoI’m impressed with how many bugs (security and otherwise) have been fixed and new features included [0] in the 1.0.1 release, considering the first public release (1.0) was only 5 days ago. [0]: https://ghostty.org/docs/install/release-notes/1-0-1 https://ghostty.org/docs/install/release-notes/1-0-1
- aumerle 2y ago[flagged]
- sevg 2y agoIt’s interesting how singularly passionate you are about Kitty, with almost all of your comments for the last year (or longer) being about Kitty. Don’t you have something more interesting to do with your time than to find opportunities to say: nah Kitty is better ;) I was just finding something to be impressed about, considering it has only just gone public and open source (as opposed to a mature project with established GitHub presence and flow of contributions).
- aumerle 2y agoYup kitty revolutionized my terminal experience, hence the passion. I am sorry but since you seem to be passionate enough about ghostty to try to shill it in a article about a security vulnerability in it, I don't think you have a leg to stand on when it comes to complaining about my posts. If you want to claim that ghostty is developed very rapidly it behoves you to do a little research and compare it against its peers before making that claim.
- sevg 2y agoWhat a strange reply. Kitty has been my terminal for years. I haven’t even used ghostty. I’m not shilling anything. Good grief. Try looking in a mirror. I was making a good faith comment just adding something positive. No need to turn it into a war. It’s strange (and just wrong) that you think I need to review the development velocity of all other projects before being impressed by something. Actually, no. To be impressed by the rainbow outside my window, I need not have seen and reviewed all other rainbows.
- aumerle 2y ago[flagged]
- sevg 2y agoImplying I’m a liar is a silly cheap shot. I’ve made zero HN comments about Firefox, Thunderbird and Blender. But I must be lying when I say I use those every day. You seem to have interpreted my original comment as a declaration of ghostty’s superiority. It wasn’t. Not every positive comment about a piece of software must also be interpreted as an attack on another piece of software, such that you have to come to its defence. Though perhaps you will tell me I’m forbidden from being impressed by any terminal other than Kitty, and certainly not God-forbid actually share that thought on HN!
- aumerle 2y ago[flagged]
- sevg 2y agoIt’s actually possible to make a positive comment about something and for it to be sincere. These are not mutually exclusive. Though it seems if there’s a positive comment about a terminal that you don’t personally think deserves it, the commenter must be a shill. Honestly quite bizarre how this sub-thread has turned out. What I thought was an innocent comment, you’ve turned into ghostty vs kitty. Not everything has to be turned into Vim vs Emacs, systemd vs anti-systemd, or which is objectively the best terminal. It’s possible to be impressed with ghostty’s release velocity without it being a judgment about Kitty or any other terminal or software project. But alas, in order to make a positive comment about ghostty, I must have already had a proven history of making positive comments about other terminals ;)
- throwawaykitten 2y agoFYI: aumerle is kitty's maintainer. i don't know why he is talking about the project as if unaffiliated.
- sevg 2y agoOh boy, that actually explains a lot! And this whole time he was accusing me of being insincere XD Also explains why he suddenly had no time to talk further when ghostty’s author offered to have a call elsewhere in this thread. Just here to advertise his terminal. I must say, I quite like how ghostty’s author has conducted himself. Might give ghostty a try once it’s packaged for my distro and first few rounds of bugfixes are in.
- fmajid 2y agoLike Julius Caesar, who used to write about himself in the third person laudative demonstrative ("ille")?
- saagarjha 2y agoLike, this is Kovid? This has to be a violation of the site guidelines.
- throwawaykitten 2y agoyes: https://news.ycombinator.com/item?id=13342516 https://news.ycombinator.com/item?id=13342516
- mitchellh 2y agoKitty is a great terminal and Kovid does excellent work. I have a ton of respect for him. Ghostty (disclaimer: I’m the creator) could also be and I appreciate anyone who thinks so. There doesn’t have to be a winner/loser mentality! The big picture is to get more people to use the terminal more for cases it’s good for. Infighting amongst people who already like terminals is counter productive, in my opinion.
- pwdisswordfishz 2y agoOh, did he start actually fixing vulnerabilities instead of insisting they aren't there while repeatedly being given PoC exploits? In case someone didn't know, the infamous Calibre bug report: https://bugs.launchpad.net/calibre/+bug/885027 https://bugs.launchpad.net/calibre/+bug/885027
- rurban 2y agoActually usable now, or still entirely insecure?
- throwawaykitten 2y agoit's good practice to note when you're the maintainer :) still if you insist on direct comparison, ghostty addressed 5x as many issues in half the time
- mitchellh 2y agoJust cross posting my lobsters post: I want to say thanks to @dgl for reporting this, and this article is also expertly written. I also have to say for me personally its quite embarrassing because as I told @dgl when he reported this: I’ve studied his work before and made it a note to test Ghostty against his past discoveries prior to release. And I… quite simply forgot. I didn’t make an issue for myself so it slipped away and here I am with egg on my face. I’m sorry! But, I appreciate @dgl for the security report, reviewing the fix, and continuing to be an active user of the terminal. I also shared with him some broader thoughts on terminal security in general. Addressing terminal security in a more fundamental way is one of the first proposals I want to make regarding terminal innovation. My thinking is still too early and under-researched for a formal proposal. But my general feeling having built a terminal over the past 2 years is that the security surrounding escape sequences is fundamentally flawed and poking one by one at these sequences to try to make them individually safe doesn’t feel like the right long term solution. The surface area is too large and the complexity of some of the newer sequences too high (i.e. Kitty Graphics) to be confident in secure implementations. DoS is far too easy with terminals (Ghostty has a handful of known DoS attacks, but so does pretty much every other terminal I know of). And some legacy sequences are just kind of shocking to have immediately available. For example, DECCOLM is available in macOS Terminal.app. If you issue a DECCOLM (CSI ? 3 h I believe), Terminal.app will physically resize the window and lock it to 132 columns. You can very easily crash Terminal.app at anytime by sending enough of these (a DoS attack). There are many more. Part of my thinking is trying to design a mechanism that can effectively create something akin to either CPU protection rings or OpenBSD’s pledge() syscall. Whatever the mechanism, the general idea is: reduction of capability. For example, it makes sense for a shell to be extremely powerful. It’s literally a code execution device. However, it doesn’t make much sense for cat to be able to execute arbitrary escape sequences (which it does today in any terminal). Whether it is the shell or cat itself, something should be able to tell a terminal: “hey, only execute some subset of escape sequences (or none at all).” For cat, that might be none or perhaps just SGR sequences (styles, colors, etc.). The insecurity of cat-ing or tail-ing any form of data that could contain user-generated data is hopefully well known at this point… As I said before, this thinking is all still very raw and I don’t have anything concrete to proposal. I want to share this because I want folks to know that I’m thinking about it, and perhaps others may be interested in thinking about it with me… if so, please contact me. I’ve already shared this line of thinking with @dgl as well.
- rollcat 2y agoI really wish that 1% of the sustained effort that is currently being devoted to building terminal emulators and TUI applications was collectively redirected at researching a better future to fill this niche. Terminal emulators and TUI applications belong with the DMG Gameboys, Commodore 64's, and DOSBoxes: as a historical curiosity and something for the enthusiasts to enjoy after hours. But we've come to rely on them almost to the point where they're being fetishised; most of us using this technology nowadays aren't even questioning its negative impact. We need better command line / REPL environments. We need better cross-platform GUI toolkits. We need better remote access. And we need to let go of the TV teletype.
- deleted 2y ago[deleted]
- SirHumphrey 2y agoIt's X11/systemd/ipv4 problem. People agreeing there is a problem doesn't mean that any single solution will be accepted. With terminals you have a system that works with anything from HPC-s to serial devices. An alternative would probably need to drop support for something, meaning congratulations: The number of standards increased by 1 - probably 2 by the time that people unsupported by the modern alternative decide that they too would like something new. The current effort can at least be pointed towards something.
- vacuity 2y agoI think you're both right in that we need standards, and we'll get them but with fractures, but at the same time we could try harder to reduce the incidence of fractures. Because at the end of the day this is all a social problem, and social problems can only be fixed by the society coming together.
- rollcat 2y agoI don't think we need a new standard (the web is already a standard, and PWAs/Electron build on top of it), we simply need better incentives/trade-offs for people who would like to write portable software, but are stuck between TUI and a hard place. I'm weirdly attracted to Tk (with Tcl or Tkinter). It's not shiny, but it's very practical.
- wslh 2y agoIt is worth mentioning my prior report on Bugtraq from 1999 [1], which predates that Bugtraq 2003 report. I recall there were earlier reports elsewhere, though I'm uncertain if I made my exploit publicly available. What stood out about this type of exploit was that it could be triggered simply by a banner in FTP/Telnet/SSH. [1] "Kvt bug": <https://seclists.org/bugtraq/1999/Sep/432 https://seclists.org/bugtraq/1999/Sep/432>
- wunderwuzzi23 2y agoAn important new attack vector are actually CLI LLM applications. During prompt injection an attacker can cause such ANSI escape codes to be emitted! Check out this post to learn more about Terminal DiLLMa and how to mitigate it: https://embracethered.com/blog/posts/2024/terminal-dillmas-prompt-injection-ansi-sequences/ https://embracethered.com/blog/posts/2024/terminal-dillmas-p...
- MrLeap 2y agoThis is fascinating. I was just playing around with this pretty printing library in .net and I wondered how security critical such a thing was, and whether or not it could be trusted. https://spectreconsole.net/ https://spectreconsole.net/ Things like this make me a little more cautious about standard out in general! More research to do.