|
|
|
|
|
by buildzr
2535 days ago
|
|
That threat model essentially prohibits "tmux attach", which allows an attacker running as your user to connect to your terminal session, so I don't think it's a particularly useful threat model here. That's basically exactly what we signed up for by using tmux. |
|
You do appear to be correct that it's exploitable via other, also trivial, means. That does not make the situation any less bad.