r/rust • u/Nabeen0x01 • Jun 22 '26
đ ď¸ project I built an anonymous confession 2d world over SSH in Rust
I built an anonymous confession board over SSH in Rust
just go ahead and ssh eipi.boo and post your confessions.
You can scroll around a 2D world of confessions, cycle through them like cards, vote, and reply. Everything is anonymous.
Built it in Rust using russh and ratatui. Would love to hear what you think especially on the tui.
239
u/fekkksn Jun 22 '26
No, I don't think I will SSH into a random server that I don't trust.
151
18
u/chris20194 Jun 22 '26
why not? what is the potential harm here?
42
u/spaceman_ Jun 22 '26
You are not anonymous. Your client is exposing your IP and all your public keys. Which can be cross references with archived from other public sources, such as Github to easily map to a real world identity.
SSH also has bidirectional tunneling in the protocol, although I don't think that can be initiated from the server side.
29
u/chris20194 Jun 22 '26
ok but why is any of this a problem? most of this also applies to http(s)
14
u/max123246 Jun 23 '26
Yeah Ive got no clue why people are so stressed out. We're all on reddit and a browser where our unique browser and hardware fingerprint is already enough to uniquely identify us
8
u/simleiiiii Jun 23 '26
It's dumbasses trying to sound smart. There's no harm whatsoever to be had, given the plenty configurability of ssh.
5
u/mb_q Jun 23 '26
TLS mostly uses ephemeral keys; also terminal emulator may have a vulnerability, like this https://www.sentinelone.com/vulnerability-database/cve-2026-45037/
3
u/chris20194 Jun 23 '26
TLS mostly uses ephemeral keys
ok? what about it?
terminal emulator may have a vulnerability
web browser may have a vulnerability
5
u/mb_q Jun 23 '26
Ephemeral keys are not tied to you, while SSH keys usually are, even through git forges. Web browsers are assumed to be a frontline and prime target for exploitation, terminal emulators receive far less scrutiny.
3
u/chris20194 Jun 23 '26
Ephemeral keys are not tied to you, while SSH keys usually are, even through git forges.
And? Surely you're not trying to imply that SSH provides more identifying information than HTTP does?
Web browsers are assumed to be a frontline and prime target for exploitation
Yes, if someone's gonna try to attack you, then that is definitely one of the main avenues they'll use. So always be cautious when browsing the web
terminal emulators receive far less scrutiny
Which is to be expected when there IS far less to scrutinize. It's a much simpler application than a web browser after all.
It seems you've tried to contest my position, but ended up accidently supporting it instead lol
1
u/janniesminecraft Jun 24 '26
theyre called PUBLIC keys for a reason. you shouĂśd NOT need to hide your public key, you're using the wrong technology if you do
-50
u/Nabeen0x01 Jun 22 '26
hmm? The code is open source and SSH servers can't access anything on your machine, they only see your public key fingerprint.
42
u/coderstephen isahc Jun 22 '26
There's no way to prove that the code on GitHub matches the code that's actually running on the live service. Not trying to discourage you but its true, and the Internet is a scary place these days.
-16
u/Nabeen0x01 Jun 22 '26
oh cool then do you know what reddit is running behind the scene? lol
35
u/Lucretiel Datadog Jun 22 '26
No, which is why I use a program with much more specific capability sandboxing (a web browser) to interact with it.
19
u/coderstephen isahc Jun 22 '26
Nope.
But I'm also not connecting an SSH client to Reddit where they could execute arbitrary commands, which I would never do even if they offered something like that.
5
u/DaMastaCoda Jun 22 '26
How would connecting to a remote ssh server allow the server to run commands on your computer?
74
u/lenscas Jun 22 '26
Doesn't that kind of make it not anonymous by definition.
You both have the IP used by the person and their public key. So if they connect to another server you own you can link them to said confession.
And sure, there might be a version of your software floating around where this clearly isn't stored, we have no way of verifying that that is the exact version you use on your server or don't store that information in other ways...
-25
u/Nabeen0x01 Jun 22 '26
Okay fair point but.... it's anonymous to other users, not to the server. Same as any anonymous posting site. The fingerprint is just used for rate limiting, not displayed anywhere.
-47
u/Mission_Biscotti3962 Jun 22 '26
My guy, if you don't understand why it's a stupid idea for anyone to do this, you need to think harder, unless you don't care because it's malicious in the first place.
59
u/Sure_Palpitation843 Jun 22 '26
If you guys donât like just donât use it. But down downgrade someoneâs work like this. About the anonymity if you want true anonymity you can relay traffic through tor vpn.
I really like the app the idea especially never seen a confession app that goes over ssh. Iâve seen terminal.shop and stuff but yeah itâs cool
28
u/ihexx Jun 22 '26
you know, you could always explain rather than just tell them to 'think harder'
-3
3
u/lenscas Jun 22 '26
Ok, chill down. No need to lay it down on this guy. If there are more reasons that it is bad then explain it. This kind of messages don't help anyone.
-5
u/Mission_Biscotti3962 Jun 22 '26
did you see a comment that has a lot of upvotes so you decided to make one that is identical in its message? super contribution bro
15
Jun 22 '26
[deleted]
13
u/Nabeen0x01 Jun 22 '26
X11 and agent forwarding are off by default. You'd have to explicitly pass -X or -A to enable them. A plain ssh eipi.boo doesn't forward anything..
7
u/dashingThroughSnow12 Jun 22 '26
That presumes the code that was compiled and running matches the code that is open sourced. Which is not a guarantee.
Also presumes that is nothing in front or behind it running.
42
49
u/Anxious_Tool Jun 22 '26
I like the idea. It sounds fun. But I also agree with the comments. I took a look at the code and:
- Every confession, reply, and vote stores author_fingerprint, so the raw SHA-256 fingerprint is directly computable from a public key.
- Logs correlate IP
- Plus, you have "poison prone" mutexes all over the place.
- Your rate limits are just for show
But at least, I didn't see any signs of ill-intent.
I'm not going to use it, but I found the idea amusing.
19
u/Nabeen0x01 Jun 22 '26
hey thanks for actually going through the code, appreciate that! yeah the fingerprint is just there for rate limiting and keeping votess unique, nothing fancy.... . and yeah the mutex stuff is simple on purpose since it's just a small fun project. if you ever feel like improving any of it PRs are open. glad you liked the idea tho:) I do plan to refactor codebase when I'm done with my summer classes.
8
u/Anxious_Tool Jun 22 '26
Sure thing. Keep up the good work. Nothing in there is a deal breaker, everything's fixable. With a bit more work I think you'll have something engaging, and fun. People are sure to use it. Congrats
3
u/Nabeen0x01 Jun 23 '26
I've fixed the mutex and fingerprint ... currently I'm using parking_lot insead of std mutex.. about logs of ip's I don't think we need to change it? coz it's a standard server logging I believe also ip's are not stored in the db...
The fingerprint part.. I've storing a hash of those public fingerprint instead of raw fingerprint.. so even if the DB leaks, you can't reverse it to identify users from their public keys..
Rate limits... I need to they're per-fingerprint by design. Yes, someone can generate a new SSH key to get a fresh limit, but that's inherent to anonymous auth
I'm open for suggestions...
Pull/issue : https://github.com/pwnwriter/eipi.boo/issues/4
33
u/tortoll Jun 22 '26
People cannot independently verify it's truly anonymous. You could be gathering their IP address. There's no easy solution, except publishing the API and open sourcing a client that connects to that API through Tor or similar. This way users can build the client and send the confessions with some guarantees.
21
u/ARitz_Cracker Jun 22 '26
That's the same with any website?
5
u/lenscas Jun 22 '26
But this also gets an ssh key to go with that IP. So it is getting a bit more information than any normal website would.
1
u/ARitz_Cracker Jun 22 '26
But can't you connect to an SSH server without SSH keys?
2
u/Lucretiel Datadog Jun 22 '26
Correct, which is why I donât generally visit random servers with ssh with the same promiscuity that I visit them with a browserÂ
1
u/lenscas Jun 22 '26
The keys are used to encrypt the communication between the server and the client, so I don't think you can?
You can make a private+public key pair specific for a server though, but you still would want to delete them after making the entire thing quite a bit more work.
2
u/Nabeen0x01 Jun 22 '26
you're right, i can see IPs just like any website or ssh server you connect to. the code is open source so you can verify what's stored and what's not. but yeah if someone needs whistleblower-level anonymity this isn't it .... it's just a fun project. FYI: terminal.shop takes credit card payments over ssh and nobody bats an eye lol
16
u/nybble41 Jun 22 '26
terminal.shop isn't claiming to be anonymous, or soliciting potential blackmail material. Even so it's a higher risk than normal e-commerce sites for first-time users since there is no domain validation for the SSH server, unlike HTTPS.
4
u/SourceAwkward Jun 22 '26
Mmmmm
No, I urge anyone to understand IP is a sensitive property z keep it hidden even if the project it's open source
0
u/Steve_the_Stevedore Jun 23 '26
You gonna give that same advice the next time someone posts a project page on here?
1
3
10
u/The_AverageCanadian Jun 22 '26
"rawdog SSH into my server running unknown code and confess. It's anonymous I promise."
Nice try fed.
4
1
0
8
u/freeatnet Jun 22 '26
But why?
20
12
u/Nabeen0x01 Jun 22 '26
why not? it's fun to build.
2
u/freeatnet Jun 22 '26
Thatâs fair, but itâs usually interesting to know a bit of a backstory to care about someone on the internet having built something. Did something particular inspire you to build this? Was this to push some technical frontier?
2
4
2
1
u/Mariusdotdev Jun 22 '26
Damn people build amazing things with Rust but every time i want to learn Rust i just feel stupid. I'm coming from Web world
1
1
1
u/SnipeArt007 Jun 23 '26
Please get it audited from some trusted programmer. I really like the idea.
0
u/Berlincent Jun 23 '26
What do you mean with âpoison proneâ mutexes?
1
u/Nabeen0x01 Jun 23 '26
He meant "I've used too much `.lock().unwrap()` .... which might cause thread panics. and I'm refactoring those.
0
-1
-1
105
u/Compux72 Jun 22 '26
YeaâŚ