22 ms·
iTerm2 critical security release
- wk_end 2y ago> A bug in the SSH integration feature caused input and output to be logged to a file on the remote host. This file, /tmp/framer.txt, may be readable by other users on the remote host. Curious about how this happens. What does "framer" mean, here?
- formerly_proven 2y agoSounds like something dropped in the code for debugging purposes and accidentally released.
- CameronBanga 2y agoHere's the commit where it was reversed, if you want to take a look and dive in. Looks like unfortunately a logging feature that he has was set to 1 instead of 0 and wasn't reset before compiling. https://gitlab.com/gnachman/iterm2/-/commit/014ba7ec40fc790f650ad73ae7ff9ca7a6964aed https://gitlab.com/gnachman/iterm2/-/commit/014ba7ec40fc790f...
- jey 2y agoiTerm2 increasingly seems too complex and bloated to me, with too many security issues. I haven't shopped for a new terminal emulator on macOS in a long time, but perhaps it's now time. I should also get around to switching to tmux, now that GNU Screen seems to be stagnant...
- slavomirvojacek 2y agoI switched to Warp, much snappier, some AI features, overall very good experience. Also Ghostty is apparently good.
- baq 2y agoI’ve been using tmux for over a decade because screen was a bit on the legacy side back then
- retrofuturism 2y agoI recently gave Ghostty a chance and have since switched over from iTerm2 completely. It's very familiar and polished.
- hmeh 2y agoSame. So far so good.
- akerl_ 2y agoProbably worth noting that Ghostty was very recently vulnerable to an old/familiar class of terminal vuln that bit a bunch of older terminal applications a while back: https://dgl.cx/2024/12/ghostty-terminal-title https://dgl.cx/2024/12/ghostty-terminal-title So moving to a newer / less "bloated" terminal may also just wind the clock back and cause you to encounter a similar sequence of vulns again, like some kind of unfortunate real-world "New Game Plus".
- jolux 2y agoHaving a vuln that many other terminal emulators have had is pretty different from the string of unique and extremely bad vulns that iTerm has had over the years. It’s possible that we’ll see similar from Ghostty, but it’s a much newer and I believe smaller codebase, so I’m willing to give it a second chance.
- akerl_ 2y agoI've been using iTerm daily for something like a decade at this point and I'm struggling to think of any examples of this string of extremely bad vulns. There's this one, which is specific to SSH integration. There was CVE-2024-38396, which is the window title escape sequences I was talking about above. What others am I missing?
- jolux 2y agoHow about making DNS requests for everything you hover over to determine if it’s a URL? https://www.bleepingcomputer.com/news/security/iterm2-leaks-everything-you-hover-in-your-terminal-via-dns-requests/ https://www.bleepingcomputer.com/news/security/iterm2-leaks-...
- 2OEH8eoCRo0 2y agoI don't use Mac but what's wrong with the default? > GNU Screen seems to be stagnant Is it stagnant or mostly complete?
- betaby 2y agoComplete I would say. However Mac uses GNU software from around 2006, since around that time a lot of GNU software switched from GPLv2 to GPLv3. That means Mac ships GNU screen version 4 from 2006, while latest version is 5.
- walterbell 2y agov4 2006: feature complete, survived 18 years of attacks v5 2024: new auth functionality, survived 4 months of attacks
- brabel 2y ago> I don't use Mac but what's wrong with the default? Nothing, it works great. As someone who tried a bunch of alternatives: sorry but it's a waste of time unless you look at the long list of iterm2 features (terminal.app has many of them anyway) and think you might use those often (I don't, quite happy with my other apps covering for most of the features missing from the terminal.app): https://iterm2.com/features.html https://iterm2.com/features.html
- lelandfe 2y agoI try out the new apps each year and always go back to Terminal.app. My one gripe with it was that Opt-Del didn't delete words, which I learned last year can be fixed by Preferences > Profiles > Keyboard > Use Option as Meta key Long live Terminal.app
- Klonoar 2y ago“Too complex” and “bloated” are catch-all that you should consider expanding further on. I don’t personally iTerm2 to be be either of those.
- kergonath 2y agoIt is a bit slow, though.
- zenapollo 2y agoWould xpipe be a candidate? It’s also quite feature packed, but i was pleasantly surprised how nicely it got out of my way
- paulddraper 2y ago> now that GNU Screen seems to be stagnant... That's not a new thing...
- Aloha 2y agoWhat else does it need? I get old code smell, and why folks might want something architecturally different, whatever - but screen is functionally feature complete.
- icedchai 2y agoI've considered "screen" complete since I started using it over 30 years ago.
- Aloha 2y agoSame - I'm at about 20 years give or take. It also has every feature known to exist in this space. I agree though that the world is moving in the way of tmux - I'll get around to switching occasionally.
- cozzyd 2y agoVertical splits? (I know they can be patched in)
- deleted 2y ago[deleted]
- jey 2y agoI recently ran into a bunch of problems running neovim under GNU Screen with `TERM=screen.xterm-256color`. There was some kind of problem relating to GNU Screen's parsing and re-transmit of certain full-color terminal escape codes. I don't remember the details right now, but what I know is that building the latest from source didn't help. (I wish I could remember the specific issues)
- JohnBooty 2y agoI haven't looked super hard, but an iTerm feature I "gotta have" is triggers - regexps that match lines of text in the terminal and do an action. You can do some complex stuff with them, but I "just" use them to highlight specific things when tailing output. Some of it might be possible with grep, but probably not
- mhink 2y agoI really like alacritty + tmux, personally.
- dylan604 2y agoI have used Terminal.app since 10.0, and have never felt like it needed replacing. What is lacking in Terminal that would improve my day to day by using a different app?
- Vegenoid 2y agoIn my opinion, the most notable feature missing from Terminal.app is 24-bit color support. This is a standard feature in modern terminal emulators, and is one that I enjoy very much. But for many people, that is not a feature that makes a big difference.
- tom_ 2y agoThat's a question that only you can answer. We have no idea what your average terminal activity involves. (I can't remember why I switched. It must have been 10 years ago now, maybe more, and I've stuck with iTerm2 ever since (even though it annoys me with a new beta update practically every time I launch it). It could have been nothing fancier than the vertical window split. But there was definitely something that persuaded me to change!) EDIT: this did get me wondering, and I noticed two things it does have that it looks like Terminal still doesn't: configurable mouse selection word boundary chars, and implicit copy-to-clipboard on selection. As an inveterate mouse selector, I wonder if it was these. I might well actually have the word boundary chars still set to the default ("/-+\~_." is what I've got), but I do use the click-to-copy a lot.
- jonstewart 2y agoThere's a mini-renaissance going on with new terminal tools, like tmux, neovim (which has an ecosystem of plugins itself), htop, and many more (https://github.com/rothgar/awesome-tuis https://github.com/rothgar/awesome-tuis). They take greater advantage of 24-bit color, "nerd" fonts (that have icons for glyphs), some graphics capability, and so on. I used Terminal for many years, too, but switched to iTerm2 a little over a year ago as I wanted to learn neovim.
- lolpanda 2y agoI'm a heavy use of tmux integration in iterm2. this allows seamless mouse scroll in a tmux window. I haven't seen any other terminals that provide the same tmux support.
- jitl 2y agoWezterm doesn’t have tmux integration but instead implements multiplexing natively, meaning if you install it on a remote, it will host a mux server you can attach to over ssh. Pretty cool, and much faster/lower latency than tmux.
- Fnoord 2y agoStill use GNU Screen? Both GNU Screen and tmux had security issues in past, but GNU Screen had worse ones and that is why I switched. Zellij is a Rust terminal multiplexer, might wanna look into that. What I especially love about it, is tge discoverability of the keybinds. TUI wet dream.
- waynesonfire 2y ago> GNU Screen seems to be stagnant... Not at all, it just had a release a few months ago, GNU Screen v.5.0.0 is released posted by anaumov, Wed 28 Aug 2024 09:41:30 PM UTC
- mattpavelle 2y ago> A bug in the SSH integration feature caused input and output to be logged to a file on the remote host. This file, /tmp/framer.txt, may be readable by other users on the remote host. Oof. This is nasty. Some folks may not have access to some machines that they've SSH'd into anymore where files like this may or may not exist.
- rad_gruchalski 2y agoThis seems relevant: When does this occur? --------------------- The issue occurs if both of the following conditions are true: 1. Either: a) You used the it2ssh command, or b) In Settings > Profiles > General, the Command popup menu was set to "SSH" (not "Login Shell", "Command", or "Custom Command") AND "SSH Integration" was checked in the SSH configuration dialog. That dialog is shown when you click the Configure button next to the ssh arguments field in Settings. 2. The remote host has Python 3.7 or later installed in its default search path.
- mattpavelle 2y agoYeah #1 reduces the surface area for sure, #2 maybe not so much :)
- Kwpolska 2y agoLooks like a case of print() debugging making it into production: https://github.com/gnachman/iTerm2/commit/63ec2bb0b95078a97abbb94cf28c4a42d1b67f23 https://github.com/gnachman/iTerm2/commit/63ec2bb0b95078a97a... https://github.com/gnachman/iTerm2/blame/5db0f74bf647f6d53ea33d2491f9b8e4972c2e03/OtherResources/framer.py#L28 https://github.com/gnachman/iTerm2/blame/5db0f74bf647f6d53ea...
- mulhoon 2y agoIt’s been around for 3 years?
- CameronBanga 2y agoAbout six months. File was originally authored a few years back, but looks like this slipped in here: https://gitlab.com/gnachman/iterm2/-/commit/5db0f74bf647f6d53ea33d2491f9b8e4972c2e03 https://gitlab.com/gnachman/iterm2/-/commit/5db0f74bf647f6d5...
- Kwpolska 2y agoDisabled by default until 7 months ago.
- Waterluvian 2y agoIn typescript dev I made “console.log” a linting error that cannot be merged. The occasional legitimate need uses console.info I think print debugging is fine. It has a time and place. But ideally find a way to protect yourself from accidentally leaving it in. It’s such an easy mistake to make.
- MiscIdeaMaker99 2y agoI would love to know more about how this got discovered and figured out. I can imagine some sysadmin pull their hair out, thinking they've got some infected system, but then find out it was some bug with their terminal emulator.
- walterbell 2y ago> got discovered and figured out Unapproved usage of the exploit?
- jcalx 2y agoI know it's largely personal preference but are there any strongly compelling reasons to use iTerm2 over stock Terminal on macOS in 2025? Despite recommendations, I've been wary of security and privacy issues much like this SSH bug.
- billowycoat 2y agoThere are reasons. Whether they are compelling or not, largely depends on what software you want to run. https://textual.textualize.io/FAQ/#why-doesnt-textual-look-good-on-macos https://textual.textualize.io/FAQ/#why-doesnt-textual-look-g...
- BoingBoomTschak 2y agoTwo main reasons I switched is that iTerm can actually display bitmap fonts without mangling them (Terminal has anti-aliasing always on) and that it handles the difference between left and right Alt (needed because AZERTY layout + emacs).
- ibejoeb 2y ago>Terminal has anti-aliasing always on There's a setting under Profiles/Text in the Text section. It's the first checkbox. Does that work, or is there a bug?
- eschatology 2y agoI am using bitmap font with AA off in Terminal.app so this is incorrect
- biwills 2y agoKitty (https://sw.kovidgoyal.net/kitty https://sw.kovidgoyal.net/kitty) has been my go to for many years and with tmux it's fantastic. I have heard a lot of great things about https://ghostty.org/ https://ghostty.org/ but haven't had a chance to check it out edit: oops, I misread your question as "what alternatives are there"
- 2y ago
- urronglol 2y ago[flagged]
- st3fan 2y agoI'm done with iTerm2. This was a great terminal when it was basically Terminal.app + missing features but over the past years it has grown into the proveribal "Kitchen Sink" and now does SO MANY things that I just don't care about. iTerm2 has become a huge app with many many knobs and levers and all kinds of functionality and integrations. I am not surprised at all that (security) bugs are found. More code, features, integrations means more potential for security issues. I switched to Ghostty, yes which had a security issue last week!, but at least it is a pretty minimal app with so far no intent to meet iTerm2 in terms of functionality.
- lucasoshiro 2y ago> does SO MANY things that I just don't care about. The integration of iTerm2 with Fish was so buggy that I needed to disable, then I lost some features like imgcat... These bugs persisted while they were introducing AI features that I really don't care (it's a terminal, why would we need AI???). I think it's time for me to move on... I don't need too much, just something that works as good as Konsole does on Linux distros. The comments here (yours included) made me consider using Ghostty.
- Philpax 2y ago> These bugs persisted while they were introducing AI features that I really don't care (it's a terminal, why would we need AI???). Many terminal programs, especially older ones, are known for having confusing or unintuitive interfaces, especially if you use them sparingly and you need to do something specific that can't immediately be gleaned from search results or from the man page. I've personally found Claude to be tremendously helpful for these cases; I am now much more confident in my use of ffmpeg, as Claude can often zero-shot the invocation for my particular need, or give me the opportunity to follow up and narrow the details of the problem. Given that, I'd happily welcome the iTerm2 integration, which I'm led to believe was optional, as I could readily specify the behaviour / action I want in natural language and have the AI produce the correct invocation without having to leave the terminal. This could also be addressed through a CLI application to invoke a LLM (i.e. simonw's `llm`), but that's not as convenient as having the terminal itself insert the LLM's response for evaluation and execution.
- paxys 2y agoThat sound you hear is IT admins worldwide scrambling to delete /tmp/framer.txt from all their servers.
- NelsonMinar 2y agoHow does a bug like this last for so many months without being noticed? Did no one notice a weird file in /tmp and wonder where it came from? The one with their ssh session history in it?
- zamadatix 2y agoGiven the purpose of the /tmp directory it seems an unlikely source for one's afternoon reading. I wonder what % of iTerm2 users use this integration feature as well. I didn't even know it existed.
- runlevel1 2y agoPerhaps not that many people were using `itssh` or replaced the initial profile command with SSH + SSH integration.
- kccqzy 2y agoIt sounds like a rarely used feature of iTerm2. I have not even heard of it despite using iTerm2's shell integration and tmux integration for a long time until I switched to Linux.
- kelnos 2y ago> I deeply regret this mistake and will take steps to ensure it never happens again. I always get a little... sigh-y when I read statements like these. What steps? I'm not even sure what I would do to ensure something like that wouldn't happen again. Build some automated tooling to run the software that exercises every single feature it has, and capture system calls to ensure that it never opens or writes to files? That sounds like a very difficult thing to do (to the point that I wouldn't even try, especially for a GUI app), but anything less doesn't feel like you can ensure it won't happen again.
- mhink 2y agoGiven the brevity of the security report, I figure the author wanted to get the relevant details about the *incident* posted as fast as humanly possible. However, it does seem appropriate to acknowledge that just because they're being terse doesn't mean they don't understand how big of a mistake it was. That being said, I would also strongly expect a more in-depth blog post following up, with details about just the sort of thing you're mentioning.
- smallnix 2y agoI understand the interest about this bug, but to my understanding this is an unpaid hobby project? If that's true I don't feel entitled to expect anything here.
- mort96 2y agoI think your parent comment used "expect" to mean "predict" rather than "demand"?
- lupire 2y agoYou can expect anything you want in software you use, and choose not do you software that fails to meet expectations. A software author who takes pains to publish his work and who accepts financial donations, is likely interested in maintaining his reputation and improving his skill and quality. Finally, security bugs are in a class of their own. Giving out free junk is OK. Giving out free secret poison is not.
- SamuelAdams 2y ago> Delete /tmp/framer.txt on affected hosts. Isn’t the correct fix to assume compromise and rotate all SSH keys? I imagine there will be scripts created very quickly to grab this file from any servers, so even if it is deleted soon there is no guarantee someone else has not read it.
- saghm 2y agoI'm not sure I follow. From what I understand, the issue is that literally all of stdin and stdout is potentially leaked to a globally-readable text file. ssh-keys wouldn't normally be part that leaked information (other than if you `cat` your private key, but by that logic, literally any credentials ever stored in a file or potentially even an env var would be equally susceptible). Yes, anyone with ssh access would have access, but nothing about this vulnerability seems to imply it would allow an unauthorized user to gain ssh access. It doesn't sound like this is something with a specific risk of leveraging into ssh access because the only ones who can read the file are the ones with access in the first place, so there's no more reason to suspect that now compared to any other point in time.
- varenc 2y agoAgreed. I believe this means just means that the entire contents of your ssh session is available in /tmp/framer.txt. But as long as credentials aren't part of your STDIN/STDOUT, then they shouldn't be leaked. Your ssh private key definitely would never be in there. The server you're connecting to doesn't even know your private key, just the public one.
- m1keil 2y agoSo Sudo password for example seem to be up there.
- saghm 2y agoThat's an interesting point; I think it might depend on the exact details of how stuff is getting put into that tempfile. It's possible that anything getting read in via "silent mode" (see `-s` in https://ss64.com/bash/read.html https://ss64.com/bash/read.html) might not get put into that file, but given that this was a bug rather than a feature, it would probably be better to check the source code (or try an example with an unpatched version) to be sure.
- isatty 2y agoOn the bright side this made me realize the stock terminal app has improved. I do use iTerm2 for its better rendering of text and color (and easier configuration of those things) but I don't really make use of any other features. Time to switch, perhaps.
- eximius 2y agohah! Clicking "Remind Me Later" for the update prompts works again!
- ryanmccullagh 2y agoWhy does a terminal need an SSH integration. Answer: it doesn’t and you shouldn’t use this because it is unsafe.
- ldjb 2y agoA terminal doesn't need SSH integration, but it's convenient if it does, to allow you to easily start and manage connections. Is there something inherently unsafe about such an integration?
- Xelynega 2y agoThere's something inherently unsafe with replacing an industry-standard security tool with anything. I don't think it's inconvenient enough to type `ssh -i key_file name@host` that we need to be creating more security risk to skip typing it.
- wkat4242 2y ago> I don't think it's inconvenient enough to type `ssh -i key_file name@host` that we need to be creating more security risk to skip typing it. Also, you can easily configure that in your .ssh/config file, even with different options per host or group of hosts.
- nerdponx 2y agoNobody needs anything ever but sometimes things are useful.
- decasia 2y agoI'm confused by the comments saying "Just don't use iTerm2." The same class of issue can occur for any other project, and switching is not a very effective defense against it. If anything, having an embarrassing issue like this is probably going to improve the iTerm2 project's security posture in the medium term. It's like that joke about firing the engineer who caused the incident, and the manager who retorts, "Why would I fire them? They just learned the hard way never to make this mistake again." (I'm paraphrasing.) I don't think that iTerm2 has had a notably high rate of critical security issues, and I suspect they won't make this class of mistake twice. (And if they do - then I will re-evaluate.) I suppose intuitively I would think that using the default MacOS Terminal app is a bit lower-risk than using iTerm2 or any other open source terminal emulator, as Terminal is a rather sparse piece of Apple-provided software with a low pace of change. But it's also closed source and impossible to audit, so there are tradeoffs there too.
- zitterbewegung 2y agoThere was another issue where iTerm2 added AI functionality and then after some backlash allowed the ability to turn it off. If the additional features (which is why you would use iTerm2 in the first place) start making more and more problems it is starting to make more sense to use terminal.app or alternatives.
- ratorx 2y agoThis is incorrect. iTerm2 never enabled any AI features by default (it always required an OpenAPI key, which the user had to provide). The backlash was for including an AI related feature in the default build at all. Following the backlash, I think they made it an optional plugin.
- mattl 2y agoIt should never have been anything other than an optional plugin but this doesn’t seem too harmful.
- jki275 2y ago
- loeg 2y agoThis was only for the SSH integration, not if you just ran "ssh" in iTerm? I don't see these /tmp/framer.txt files on any of the hosts I sshed to (plain ssh).
- teruakohatu 2y agoFrom the release notes it seems only if the in-built SSH integration was used and the server that a more recent (5ish year old or later) version of Python. The latter condition is probably going to exist even on enterprise dists (RHEL 9 for example will have Python 3.9 installed by default)
- welder 2y agoThe latter condition must not always trigger... I have Python 3.7 or later and none of my servers have a `/tmp/framer.txt` file.
- deleted 2y ago[deleted]
- mrichman 2y agoGlad I switched to Ghostty this week.
- teruakohatu 2y agoI feel deeply for the developer who develops iTerm for relatively very little money, and already took a lot of criticism for the AI integration, far more than was warranted. I am also also deeply concerned about my use of iTerm now. I access HPC environments where I may have access for a short period of time. I am expected to take responsibility to clear out my data after use and don't expect there to be any data leakage. If I had been manipulating PII research data in the past year and using iTerm's SSH integration I would be in a bit of a bind and have to send some really embarrassing emails asking sysadmins to see if these logs exist, and if they belong to me, followed by disclosing data had been leaked. I use some of the more advanced features but at this point wonder if I should be using any features beyond the basic, and then I may as well be using another terminal. I haven't found a cross-platform editor that feels as native on MacOS as iTerm, ghostty included.
- shwouchk 2y agoI highly recommend wezterm.
- rcruzeiro 2y agoI tried WezTerm recently but I unfortunately could not type backslashes on an ISO keyboard. There were other minor annoyances such as new tabs always opening on the last directory I was at and not my home directory (this was something that could be configured, but I never managed to do it). Ultimately, it was the problem with the backslashes that drove me back to iTerm. https://github.com/wez/wezterm/issues/4051 https://github.com/wez/wezterm/issues/4051
- soheil 2y agoBased on what? How do you know it's not riddled with major security bugs? At least iTerm has been around for over a decade and loved by many hardcore power users.
- shwouchk 2y agoso was openssl
- xucheng 2y agoMany years ago, I reported an issue where iTerm2 leaks sensitive search history to preference files [1]. The issue was quickly fixed. But until this day, I can still find people unintentionally leak their search history in public dotfiles repos [2]. [1]: https://gitlab.com/gnachman/iterm2/-/issues/8491 https://gitlab.com/gnachman/iterm2/-/issues/8491 [2]: https://github.com/search?q=NoSyncSearchHistory+path%3A*.plist&type=code https://github.com/search?q=NoSyncSearchHistory+path%3A*.pli...
- hbbio 2y agoI always preferred alacritty which is faster and hopefully safer. Tha macOS part uses the rust `objc2` crates which I find high quality and the codebase is a joy to read.
- johnsonalpha 2y agoI’m a bit confused by the suggestion to "Just don’t use iTerm2." The reality is that this type of issue could happen with any project, and switching tools doesn’t provide meaningful protection. If anything, incidents like this often lead to stronger security practices. It’s like the old joke about firing an engineer after a mistake, and the manager responding, "Why would I fire them? They’ve just learned a lesson they won’t forget." Based on iTerm2’s track record, it doesn’t seem like they’ve had frequent critical security issues, and I doubt they’ll repeat this mistake. If they do, then it’s fair to reassess. As for the MacOS Terminal app, it might seem like a lower-risk option because it’s simpler and updates less frequently. However, being closed-source makes it impossible to audit, which brings its own risks. Ultimately, every tool has tradeoffs, and choosing the right one depends on balancing your needs with the potential risks.
- epistasis 2y ago> could happen with any project, and switching tools doesn’t provide meaningful protection Do you believe that developments practiced have an impact on security bug rate? Second, do you believe that past track record is reflective of that security bug rate? These are two reasonable beliefs that many people hold. It's a far more nuanced view than "every project could have bugs" which is a black-and-white view that does not assess risk in a useful way.
- locusofself 2y agoI just want to sing some praises for iterm2. I've been using it for work and fun for many years now and will continue to use it and send a donation again as I did once before.
- Upvoter33 2y agoAgree. It's one of the best things I use all the time.
- coolgoose 2y agoLooking at the replies here, I am not even sure how to react, it seems this community overall is going into a sad direction that just blames instead of trying to think of solutions. Most of them are just entitled and aggressive for absolutely no reason. It's perfectly fine to want to switch, or try something else, but to think other projects couldn't have issues is just naive to say it gently.
- lpapez 2y agoI think that goes for society as a whole. We should all be more emphatic and considerate. Especially around things like this - it's not the end of the world. Software is difficult and shit happens all of the time, give the maintainers a break...
- nozzlegear 2y ago> We should all be more emphatic and considerate. I'm sure it was just autocorrect being a nuisance, but you probably mean empathic.
- kevingadd 2y agoThe developer of iTerm2 has a thankless job to be sure, but the reality is that when you build this kind of software you have a certain responsibility to be thoughtful and cautious and not indirectly cause harm to others. Security vulnerabilities like this can cause actual harm, so it's understandable that people see someone fail to live up to the responsibility and they get mad. There aren't easy solutions to having responsibility. All you can do is live up to it, which sometimes means you need to apply rigor and processes that make hacking less fun, or that you need to make compromises you don't like. "to think other projects couldn't have issues is just naive" is the wrong way to look at it. You should evaluate the processes that lead to the binary (or source tarball) that you're running on your machine. Is every commit/PR being reviewed by someone other than the author? By multiple someones, ideally? Do they run automated test suites before shipping?
- rswail 2y ago
- rswail 2y agoI've used iTerm2 for as long as I've known about it, which would be maybe 10 years? I don't use much of the various SSH/mux features, 'cos I don't use multiple buffers, just multiple tabs. I like the scrollback and the footer and the integration with the shell, don;t care about scrolling speed very much, and it's sort of the "ain't broke, so why change". I'll take a look at ghostty, but not sure it gives me much. As for this security issue, it's a bug, the author found it, fixed it, announced what it was, and how to ameliorate the effects of the issue. He did that in a very reasonable timeframe and has been entirely open about it. The pile-on of moralists and what appear to be purists (and possibly early stage devs if they think process is the answer) is sorta pathetic. This entire thread is more twitter/reddit than what I've come to expect on HN.
- rswail 2y agoThis thread reminded me to make my annual donation to iTerm2's developer, who does a pretty amazing job keeping iTerm MacOS compliant and up to date.
- nose-wuzzy-pad 2y agoThis thread reminded me to make a donation as well!
- _0xdd 2y agoJust did the same. I've used this app for years and benefitted from its features. It's a shame to see some of the comments in this thread.
- mdaniel 2y agoIf one is already in the GitHub sponsors ecosystem, he accepts those too https://github.com/sponsors/gnachman https://github.com/sponsors/gnachman
- soheil 2y agoI would advice anyone using iTerm not to willy-nilly switch their terminal to one recommended by a random user here. Terminals can have a huge attack surface and many "open-source" ones are maintained by less than trustworthy developers who very easily could inject a backdoor. Sticking with time-proven projects like iTerm provides the advantage of added trust, security and basic common sense. It also seems like a huge coincidence that there are a lot of green accounts here "highly" recommending all sorts of random terminal alternatives.
- lionkor 2y agoNot sure what the replies here are on about. This is NOT a "whoopsie, can happen to any project" bug. There was code in the project that EXPLICITLY leaked stuff into the remote host. Am I missing something? Not only would switching to a different project with more eyes on it probably never do this, it would also probably never let that through PR reviews.
- thih9 2y agoAre you offering to review PRs of a different project? That’s actually very beneficial. Which project are you planning to support like this?
- lionkor 2y agoNot sure what to make of this snarky ass reply, I do plenty of open source work, not sure why that would be warranted as a reply. Just because I like open source, doesnt mean I need to do literally all the work.
- thih9 2y agoDoing open source work, while extremely cool, is off topic when it’s about other open source projects. If you’re not going to work on a project, trust those who are going to work on it. Or move to a different software I guess.
- cdeevgtg 2y agoOnly when verbose logging is enabled, which seems fine to me What's not fine is verbose logging being turned on by default, most likely by mistake
- muppetman 2y agoI thought we were all losing our mind over Ghostty anyway and iterm2 wasn't cool anymore because it's, apparently, slow?
- egorfine 2y agoiTerm2 is the app I spend the most time for like a decade or so. I feel bad for the developer. This is embarrassing and it totally could and probably will at some point happen to the best of us. So I have immediately donated and subscribed to monthly donations and I encourage everyone to do so. There should be zero doubt that the author deserves our support.
- deleted 2y ago[deleted]
- unit149 2y ago[dead]