Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> It is kind of shocking to me how TUIs are enjoying a bit of dev tool renaissance right now when the browser is such a capable platform.

Command line tools (and by extension TUIs) can be used over SSH and don't require messing around with HTTPS certificates. They also have the benefit of having the context of your CWD.



Having made`ssh mario.baby` and https://mario.baby (visa was) from the same code.. I'd choose https any day.


> don't require messing around with HTTPS certificates.

Which also means there’s no real defense against MITM attacks… at least I don’t think anyone seriously checks the host key on first connection.


Most reasonable countries have the same defense against that as you get against someone stabbing you. I don't see many security professionals insisting that you have to walk around in plate mail for some reason.


You get notified if the server key changes though. I don't think it's fair to say there's no defense against MITM.


That doesn't protect against MITM happening on the first connect.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: