Mention of Thrussh in README.md - #756
Conversation
The current phrasing makes it sound like Thrussh has stalled, which is far from true. Not contributing back is ok, misleading statements aren't.
|
Feel free to just remove the sparkles for algorithms that thrussh now implements instead of implying a tradeoff. |
|
I think I contributed enough to "your" project already. Misleading statements should just be fixed I think, for the sake of honesty. |
|
Not sure what you're trying to quote using those quote marks, and do elaborate on how "added in russh" is a misleading statement. |
|
The reason I find it misleading (feel free to disagree and explain why), is that your statements along with the sparkles, seem to imply that Thrussh has been abandonned or unmaintained, which is far from true. You chose a different side of a trade-off, I'm deeply convinced that a good engineer would find that kind of choice easy to explain. |
|
I'm sure a good engineer would not do unbounded buffer allocations based on an attacker-controlled packet length that lets you take down any I suggest you start by upstreaming some of the fixes. See if the updated README is satisfactory. |
|
By all means state that! And please explain why such a good engineer didn't try to contribute the fixes or raise the issues. Forking is fine, not contributing back is just weird. |
|
You know I did, which did not stop you from publicly lying about it on lobsters, and now you woke up from two years of doing barely fuckall about your library to harrass me here. I've corrected the factual content of the README feature list. If you have since implemented anything I've missed, feel free to open another PR.
Here's a bash oneliner that brings down your thrussh-based Nest. Encrypted with your personal Ed25519 key you use for Pijul. Consider this a responsible disclosure, but that's really on the mild side of the shit that thrussh does decrypt with |
The current phrasing makes it sound like Thrussh has stalled, which is far from true. Not contributing back is ok, misleading statements aren't.
Description
...
AI Usage
Choose the level of AI involvement for this PR.
This is not to block AI contributions but rather to speed up PR review (saves time on trying to deduce the logic behind AI hallucinations).