Comment by kjs3

13 days ago

Note that this is much more dangerous than visiting a website.

Are you being hyperbolic or do you seriously think the attack surface area of ANSI escape sequences is 'much more' than, say, Javascrpt?

JavaScript has to escape the browser sandbox, does telnet have a similar sandbox? Or can it access the system directly?

I don't know the answer but if telnet can directly access the system that seems more dangerous irrespective of the attack surface.

  • That's a very fair point, but on my system telnet is 211144 bytes. How big is a javascript runtime + browser + browser sandbox. I have no idea, but I'd be really surprised if it was less than 3 orders of magnitude bigger, and not at all surprised if it was 4 orders of magnitude bigger. There's just more places for things to go wrong.

    And, telnet isn't installed by default on many systems. So...YMMV.