Hacker News new | ask | show | jobs
by cmdrfred 4083 days ago
I was looking for something like minaterm the other day, trouble is i'd be scared to put my credentials into it. A when I think about it logically that isn't rational (putty can grab my credentials just as easily), but still.
2 comments

It's not entirely irrational. If putty wants to grab your credentials they have to ship a broken binary that once downloaded exists forever and can be examined and reverse engineered in the wild. Someone running a web service (or someone who has compromised said service) can target a particular user for a single session and the evidence that an attack occurred will only exist until a few caches get cleared.
yes, and I also would be scared to too. It's interesting thinking about why though. I think there's a significant social/psychological component to the decision.

I'd also be less scared if it was running on my own server, but it's not clear to me that this is completely logical either.