There are even examples using terminal escape codes, to hide what happened.
https://www.reddit.com/r/privacy/comments/rv964x/comment/hr4...
There are even examples using terminal escape codes, to hide what happened.
https://www.reddit.com/r/privacy/comments/rv964x/comment/hr4...
A solution is bracketed paste[1] as mentioned in earlier comments[2], which would allow the user to examine a pasted command before running it.
and that editor should not be running "inside" a terminal
-- or rather I don't understand why those that like interacting with their editor via a terminal interface don't create a new protocol that doesn't have the warts and vulnerabilities the current ancient protocol has.
e.g. Vim creating their own protocol is rather pointless if no terminal implements it, and some terminal creating their own protocol is also rather pointless without application support.
Plus there's tons of software out there and it'll take a long time for it all to be rewritten, if that ever happens. e.g. X11 will still be around for a long time as well. So you will need to remain compatible with the current protocol even if you invent something new and better, and in that sense it doesn't really fix anything., at least not right now. It might fix stuff 15 years down the line, maybe, but in-between now and 15 years everything will be more complex by having two protocols.
And all things considered, it's not that bad, IMHO. There's the KiTTY Keyboard protocol to solve some obvious UX issues with keyboard handling, which is a clear improvement and motivation, whereas some exploit vectors that don't really see live exploits isn't really.
The hairiest Emacs Lisp code I know about is the code for responding to mouse actions, e.g., clicking and dragging, and most Vim users don't even want to use a pointing device to interact with Vim IIUC. (In contrast, 80% of Emacs users who responded to a survey do not interact with Emacs through a terminal interface.)
For example, the old scripting language Tcl has its own GUI toolkit named Tk that has a pretty good reputation.
>And all things considered, it's not that bad
It seems bad enough to me to be worth re-architecting.
But in a terminal all code runs in that terminal, and terminal programs don't "link against" a terminal in the same way that you do with a GUI toolkit. You need to implement a shared protocol on both ends.
So I suppose we're not very far from this not being a problem in general.
Though I understand this also works via control codes. I hope Tilix is smart enough to filter them out from the clipboard before doing this..
edit: I tested that case out, and it works. I suppose the protocol uses quoting.