Despite Chrome being speedily updated when known security problems are discovered, the attack surface compared to a dedicated client is huge: the 2-decade-old /usr/bin/ssh + /usr/bin/xterm combo has no concept of a DOM, does not share computing interfaces available to untrusted users (e.g. shared web workers), cannot receive messages from untrusted frames (postMessage()), cannot even be addressed by untrusted content (chrome://path/to/trusted/script), does not almost transparently expose ring0 drivers (OpenGL), does not have thousands of LOC on subsystems with little battle testing (WebRTC) and so on.
Of course these features are thought to be secure, until they are discovered in the midst of a Stuxnet type scenario and suddenly everyone is patching like crazy. Wasn't Java considered invulnerable only 2 weeks ago? Look at what changed - somebody noticed it wasn't long after tens of thousands of infections already occurred, and today it is on every browser's plug-in blacklist. I can't recall the last I read about xterm in the Pwn2Own contest, or any 0-day in the past decade, nor can Google accidentally DoS my xterm because their sync service is down (happened last month).
Following from the truism that the fastest, most bug-free code is code that doesn't exist, the easiest way to reduce exposure to unknown attacks is to minimize the amount of code running. Security design 101. Using something with the complexity of a web browser to render an 80x25 vector used to administer potentially hundreds of thousands of machines is almost the antithesis of good protocol.
An OS that they may or may not update frequently.
An OS that they may or may not be logged into as an admin.
An OS that may have a keylogger running on it.
I think running SSH (or Chrome Remote Desktop) from a Chromebox is a pretty good way to have that minimal OS that is updated frequently, without admin privileges, with a lower risk of a keylogger. That I have to use two-factor to log into, even if my device is stolen.
If you don't want the risk, don't install extensions you don't fully trust. Just like any applications or services on your desktop.
Yes, I agree. The grandparent does point out a valid problem. However I believe the parent was referring to the sarcastic tone and negativity, which I also believe should be out of place here on Hacker News.
xterm is bloated and unmaintainable. Here’s an excerpt from the README:
Abandon All Hope, Ye Who Enter Here
This is undoubtedly the most ugly program in the distribution. It was one of
the first "serious" programs ported, and still has a lot of historical baggage.
Ideally, there would be a general tty widget and then vt102 and tek4014
subwidgets so that they could be used in other programs. We are trying to
clean things up as we go, but there is still a lot of work to do.
Needless to say things have not changed, it’s still ugly. It has over 65K lines of code and emulates obscure and obsolete terminals you will never need. The popular alternative, rxvt has only 32K lines of code. This is just too much for something as simple as a terminal emulator; it’s yet another example of code complexity.[0] in a technical sense, the startup focus is quite unique to HN. or maybe I don't subscribe to startup-related subreddits (since startup news is not really the reason I read HN either)
Increasingly I expect a contrarian at the top stating nothing but the obvious fact that there are security implications. Can we stop this now?
You can find quality conversations in Reddit but, more than likely, not in the default subreddits.
People have been complaining that Reddit was taking over years ago and will continue to. Strangely while people posting cat pictures is downvoted for not being productive conversation comments like this get upvoted when it contributes just as much. Heck its even in the guideline:
If your account is less than a year old, please don't submit comments saying that HN is turning into Reddit. (It's a common semi-noob illusion.)
Although I know you have been around for more then a year.
I thought it would be obvious to most readers how a tty environment is easier to control than a browser (really, just consider the number and pace of updates to your kernel/windowing system/terminal and your web browser), so I did not bother with lengthy explanations.