Skip to content

Mention of Thrussh in README.md - #756

Closed
P-E-Meunier wants to merge 1 commit into
Eugeny:mainfrom
P-E-Meunier:patch-1
Closed

Mention of Thrussh in README.md#756
P-E-Meunier wants to merge 1 commit into
Eugeny:mainfrom
P-E-Meunier:patch-1

Conversation

@P-E-Meunier

Copy link
Copy Markdown

The current phrasing makes it sound like Thrussh has stalled, which is far from true. Not contributing back is ok, misleading statements aren't.

Description

...

AI Usage

Choose the level of AI involvement for this PR.

  • Fully vibe coded
  • AI-designed, AI-coded, manually checked
  • Human-designed, AI-coded
  • Human-designed, human-coded (includes AI autocompletions and boilerplate gen)

This is not to block AI contributions but rather to speed up PR review (saves time on trying to deduce the logic behind AI hallucinations).

The current phrasing makes it sound like Thrussh has stalled, which is far from true. Not contributing back is ok, misleading statements aren't.
@Eugeny

Eugeny commented Aug 20, 2026

Copy link
Copy Markdown
Owner

Feel free to just remove the sparkles for algorithms that thrussh now implements instead of implying a tradeoff.

@P-E-Meunier

Copy link
Copy Markdown
Author

I think I contributed enough to "your" project already. Misleading statements should just be fixed I think, for the sake of honesty.

@Eugeny

Eugeny commented Aug 20, 2026

Copy link
Copy Markdown
Owner

Not sure what you're trying to quote using those quote marks, and do elaborate on how "added in russh" is a misleading statement.

@P-E-Meunier

Copy link
Copy Markdown
Author

The reason I find it misleading (feel free to disagree and explain why), is that your statements along with the sparkles, seem to imply that Thrussh has been abandonned or unmaintained, which is far from true.

You chose a different side of a trade-off, I'm deeply convinced that a good engineer would find that kind of choice easy to explain.

@Eugeny

Eugeny commented Aug 20, 2026

Copy link
Copy Markdown
Owner

I'm sure a good engineer would not do unbounded buffer allocations based on an attacker-controlled packet length that lets you take down any thrussh based server with a single packet, but what would I know.

I suggest you start by upstreaming some of the fixes.

See if the updated README is satisfactory.

@P-E-Meunier

P-E-Meunier commented Aug 20, 2026

Copy link
Copy Markdown
Author

By all means state that! And please explain why such a good engineer didn't try to contribute the fixes or raise the issues. Forking is fine, not contributing back is just weird.

@Eugeny Eugeny closed this Aug 20, 2026
@Eugeny

Eugeny commented Aug 20, 2026

Copy link
Copy Markdown
Owner

You know I did, which did not stop you from publicly lying about it on lobsters, and now you woke up from two years of doing barely fuckall about your library to harrass me here.

I've corrected the factual content of the README feature list. If you have since implemented anything I've missed, feel free to open another PR.

thrussh completely, utterly shits the bed on security, so trying to use this repo as a platform for your personal opinions on design tradeoffs is simply pathetic.

Here's a bash oneliner that brings down your thrussh-based Nest. Encrypted with your personal Ed25519 key you use for Pijul. Consider this a responsible disclosure, but that's really on the mild side of the shit that thrussh does

-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IGxkeWlYUSBHVDl4
SFMvRzB4M05MWDdCSEdCY2s2UEdYRVhSWWpkVnIwUUZzT1pVZzBZClFraFp4dVBz
QXcydndTdjkvMGNiejBLMGtEM3lIQ1BXNjlmNjFUZ0FYbU0KLS0tIDd5amZwNFkw
akJMMSsrZU1Vanl0Q3FoUW55Mkc3Wm5JcmpyMWxvaUVmTVkKh1vt7Dx7+1/lCmM1
1AuCFobNJOvBqoNWGVOZxkD5/HTdjzvIDvLtGGH/eGocseWrQ2ggZAub8P1CRiip
MuRHhKEzY39jQPRx/51E+AbJdM379AGDsCNCyO7y6q1XaXfxpMV7EsCSMrRFcfio
uGPoRY3GgEdiDyyS1Pdxo5iPL42RoYlit6ZXPgvv41bPNg==
-----END AGE ENCRYPTED FILE-----

decrypt with age -d -i ~/.ssh/id_ed25519

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants