news.volyx.in

iTerm2 critical security release (iterm2.com)

671 points by tjwds · 580 days ago · 438 comments on HN

Article summary

A critical security release for iTerm2 has been issued due to a bug in the SSH integration feature that caused input and output to be logged to a file on the remote host. The bug may have allowed other users on the remote host to access the logged data. The issue has been fixed, but it has sparked a discussion about the security and complexity of iTerm2. Some users are considering switching to alternative terminal emulators like Ghostty.

Main themes

  • iTerm2 security
  • Terminal emulator alternatives
  • Ghostty features and issues
  • Security vulnerabilities
  • Terminal emulator comparison

What commenters say

  • The security issue in iTerm2 is a significant concern and may be a sign of a larger problem with the software's complexity and maintenance.
  • Ghostty is a viable alternative to iTerm2, but it still lacks some features and has its own set of issues, including font rendering problems and limited customization options.
  • The frequency and severity of security vulnerabilities in iTerm2 are a reason to consider switching to a different terminal emulator, such as Ghostty or kitty.
  • Newer terminal emulators like Ghostty have not yet earned a reputation for security and may still be vulnerable to undiscovered issues, despite their smaller codebase and more modern design.
  • Some users are hesitant to switch from iTerm2 due to its familiarity and feature set, despite its security issues and complexity.
  • The process of transferring themes and configurations from iTerm2 to Ghostty is not straightforward and may require manual effort or waiting for updates.
  • Ghostty's quake mode is not yet fully functional and lacks some features compared to iTerm2's implementation.
  • The debate over iTerm2's security and complexity highlights the trade-offs between feature richness and potential vulnerabilities in software design.