Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

According to the website, it sends the keystrokes to an API endpoint in the internet. While nice, I‘d be concerned about the security implications of using this tool. I mean it could also „accidentally“ be sending env variables etc.?


Never mind… From the FAQ:

> asciinema rec demo.cast

„ then the recording is saved to a local file in asciicast 271 format.“


Any reason to suppose that? Any CLI tool (sending keystrokes or not) that interacts with an api could do that too.


I think it only records the terminal output(along with other metadata like timing) and not what you type(input). If you enter a password in a prompt that does not echo/display it back, it shouldn't be recorded.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: