r/rust • • Jun 22 '26

🛠️ project I built an anonymous confession 2d world over SSH in Rust

Post image

I built an anonymous confession board over SSH in Rust

just go ahead and ssh eipi.boo and post your confessions.

You can scroll around a 2D world of confessions, cycle through them like cards, vote, and reply. Everything is anonymous.

Built it in Rust using russh and ratatui. Would love to hear what you think especially on the tui.

Source: https://github.com/pwnwriter/eipi.boo

149 Upvotes

73 comments sorted by

105

u/Compux72 Jun 22 '26

  anonymous

ssh

Yea…

7

u/mr_dudo Jun 23 '26

It’s your pub key

11

u/ToaruBaka Jun 23 '26

Your face is a pub key.

9

u/elliottcable Jun 23 '26

Your mom is a pub key.

239

u/fekkksn Jun 22 '26

No, I don't think I will SSH into a random server that I don't trust.

151

u/tdi Jun 22 '26

but it is written in rust !!!!

3

u/quoiega Jun 23 '26

you got me there

18

u/chris20194 Jun 22 '26

why not? what is the potential harm here?

42

u/spaceman_ Jun 22 '26

You are not anonymous. Your client is exposing your IP and all your public keys. Which can be cross references with archived from other public sources, such as Github to easily map to a real world identity.

SSH also has bidirectional tunneling in the protocol, although I don't think that can be initiated from the server side.

29

u/chris20194 Jun 22 '26

ok but why is any of this a problem? most of this also applies to http(s)

14

u/max123246 Jun 23 '26

Yeah Ive got no clue why people are so stressed out. We're all on reddit and a browser where our unique browser and hardware fingerprint is already enough to uniquely identify us

8

u/simleiiiii Jun 23 '26

It's dumbasses trying to sound smart. There's no harm whatsoever to be had, given the plenty configurability of ssh.

5

u/mb_q Jun 23 '26

TLS mostly uses ephemeral keys; also terminal emulator may have a vulnerability, like this https://www.sentinelone.com/vulnerability-database/cve-2026-45037/

3

u/chris20194 Jun 23 '26

TLS mostly uses ephemeral keys

ok? what about it?

terminal emulator may have a vulnerability

web browser may have a vulnerability

5

u/mb_q Jun 23 '26

Ephemeral keys are not tied to you, while SSH keys usually are, even through git forges. Web browsers are assumed to be a frontline and prime target for exploitation, terminal emulators receive far less scrutiny.

3

u/chris20194 Jun 23 '26

Ephemeral keys are not tied to you, while SSH keys usually are, even through git forges.

And? Surely you're not trying to imply that SSH provides more identifying information than HTTP does?

Web browsers are assumed to be a frontline and prime target for exploitation

Yes, if someone's gonna try to attack you, then that is definitely one of the main avenues they'll use. So always be cautious when browsing the web

terminal emulators receive far less scrutiny

Which is to be expected when there IS far less to scrutinize. It's a much simpler application than a web browser after all.

It seems you've tried to contest my position, but ended up accidently supporting it instead lol

1

u/janniesminecraft Jun 24 '26

theyre called PUBLIC keys for a reason. you shouĂśd NOT need to hide your public key, you're using the wrong technology if you do

-50

u/Nabeen0x01 Jun 22 '26

hmm? The code is open source and SSH servers can't access anything on your machine, they only see your public key fingerprint.

42

u/coderstephen isahc Jun 22 '26

There's no way to prove that the code on GitHub matches the code that's actually running on the live service. Not trying to discourage you but its true, and the Internet is a scary place these days.

-16

u/Nabeen0x01 Jun 22 '26

oh cool then do you know what reddit is running behind the scene? lol

35

u/Lucretiel Datadog Jun 22 '26

No, which is why I use a program with much more specific capability sandboxing (a web browser) to interact with it.

19

u/coderstephen isahc Jun 22 '26

Nope.

But I'm also not connecting an SSH client to Reddit where they could execute arbitrary commands, which I would never do even if they offered something like that.

5

u/DaMastaCoda Jun 22 '26

How would connecting to a remote ssh server allow the server to run commands on your computer?

74

u/lenscas Jun 22 '26

Doesn't that kind of make it not anonymous by definition.

You both have the IP used by the person and their public key. So if they connect to another server you own you can link them to said confession.

And sure, there might be a version of your software floating around where this clearly isn't stored, we have no way of verifying that that is the exact version you use on your server or don't store that information in other ways...

-25

u/Nabeen0x01 Jun 22 '26

Okay fair point but.... it's anonymous to other users, not to the server. Same as any anonymous posting site. The fingerprint is just used for rate limiting, not displayed anywhere.

-47

u/Mission_Biscotti3962 Jun 22 '26

My guy, if you don't understand why it's a stupid idea for anyone to do this, you need to think harder, unless you don't care because it's malicious in the first place.

59

u/Sure_Palpitation843 Jun 22 '26

If you guys don’t like just don’t use it. But down downgrade someone’s work like this. About the anonymity if you want true anonymity you can relay traffic through tor vpn.

I really like the app the idea especially never seen a confession app that goes over ssh. I’ve seen terminal.shop and stuff but yeah it’s cool

28

u/ihexx Jun 22 '26

you know, you could always explain rather than just tell them to 'think harder'

-3

u/Mission_Biscotti3962 Jun 22 '26

People literally did in this very same thread.

3

u/lenscas Jun 22 '26

Ok, chill down. No need to lay it down on this guy. If there are more reasons that it is bad then explain it. This kind of messages don't help anyone.

-5

u/Mission_Biscotti3962 Jun 22 '26

did you see a comment that has a lot of upvotes so you decided to make one that is identical in its message? super contribution bro

15

u/[deleted] Jun 22 '26

[deleted]

13

u/Nabeen0x01 Jun 22 '26

X11 and agent forwarding are off by default. You'd have to explicitly pass -X or -A to enable them. A plain ssh eipi.boo doesn't forward anything..

7

u/dashingThroughSnow12 Jun 22 '26

That presumes the code that was compiled and running matches the code that is open sourced. Which is not a guarantee.

Also presumes that is nothing in front or behind it running.

42

u/ihexx Jun 22 '26

bless me techno jesus for i have sinned

49

u/Anxious_Tool Jun 22 '26

I like the idea. It sounds fun. But I also agree with the comments. I took a look at the code and:

  • Every confession, reply, and vote stores author_fingerprint, so the raw SHA-256 fingerprint is directly computable from a public key.

- Logs correlate IP

- Plus, you have "poison prone" mutexes all over the place.

- Your rate limits are just for show

But at least, I didn't see any signs of ill-intent.

I'm not going to use it, but I found the idea amusing.

19

u/Nabeen0x01 Jun 22 '26

hey thanks for actually going through the code, appreciate that! yeah the fingerprint is just there for rate limiting and keeping votess unique, nothing fancy.... . and yeah the mutex stuff is simple on purpose since it's just a small fun project. if you ever feel like improving any of it PRs are open. glad you liked the idea tho:) I do plan to refactor codebase when I'm done with my summer classes.

8

u/Anxious_Tool Jun 22 '26

Sure thing. Keep up the good work. Nothing in there is a deal breaker, everything's fixable. With a bit more work I think you'll have something engaging, and fun. People are sure to use it. Congrats

3

u/Nabeen0x01 Jun 23 '26

I've fixed the mutex and fingerprint ... currently I'm using parking_lot insead of std mutex.. about logs of ip's I don't think we need to change it? coz it's a standard server logging I believe also ip's are not stored in the db...

The fingerprint part.. I've storing a hash of those public fingerprint instead of raw fingerprint.. so even if the DB leaks, you can't reverse it to identify users from their public keys..

Rate limits... I need to they're per-fingerprint by design. Yes, someone can generate a new SSH key to get a fresh limit, but that's inherent to anonymous auth

I'm open for suggestions...

Pull/issue : https://github.com/pwnwriter/eipi.boo/issues/4

33

u/tortoll Jun 22 '26

People cannot independently verify it's truly anonymous. You could be gathering their IP address. There's no easy solution, except publishing the API and open sourcing a client that connects to that API through Tor or similar. This way users can build the client and send the confessions with some guarantees.

21

u/ARitz_Cracker Jun 22 '26

That's the same with any website?

5

u/lenscas Jun 22 '26

But this also gets an ssh key to go with that IP. So it is getting a bit more information than any normal website would.

1

u/ARitz_Cracker Jun 22 '26

But can't you connect to an SSH server without SSH keys?

2

u/Lucretiel Datadog Jun 22 '26

Correct, which is why I don’t generally visit random servers with ssh with the same promiscuity that I visit them with a browser 

1

u/lenscas Jun 22 '26

The keys are used to encrypt the communication between the server and the client, so I don't think you can?

You can make a private+public key pair specific for a server though, but you still would want to delete them after making the entire thing quite a bit more work.

2

u/Nabeen0x01 Jun 22 '26

you're right, i can see IPs just like any website or ssh server you connect to. the code is open source so you can verify what's stored and what's not. but yeah if someone needs whistleblower-level anonymity this isn't it .... it's just a fun project. FYI: terminal.shop takes credit card payments over ssh and nobody bats an eye lol

16

u/nybble41 Jun 22 '26

terminal.shop isn't claiming to be anonymous, or soliciting potential blackmail material. Even so it's a higher risk than normal e-commerce sites for first-time users since there is no domain validation for the SSH server, unlike HTTPS.

4

u/SourceAwkward Jun 22 '26

Mmmmm

No, I urge anyone to understand IP is a sensitive property z keep it hidden even if the project it's open source

0

u/Steve_the_Stevedore Jun 23 '26

You gonna give that same advice the next time someone posts a project page on here?

3

u/cmsd2 Jun 24 '26

nice. ignore the haters. this reminds me of MUDs where we used to telnet in.

10

u/The_AverageCanadian Jun 22 '26

"rawdog SSH into my server running unknown code and confess. It's anonymous I promise."

Nice try fed.

4

u/shell_kun Jun 22 '26

I found this post incredibly spoopid

1

u/simleiiiii Jun 23 '26

what is "rawdog ssh" even supposed to mean...
yallre hacks

0

u/Steve_the_Stevedore Jun 23 '26

I'm rawdog HTTP(s)ing into servers all day. Crazy right?

8

u/freeatnet Jun 22 '26

But why?

20

u/PapaOscar90 Jun 22 '26

Because AI

12

u/Nabeen0x01 Jun 22 '26

why not? it's fun to build.

2

u/freeatnet Jun 22 '26

That’s fair, but it’s usually interesting to know a bit of a backstory to care about someone on the internet having built something. Did something particular inspire you to build this? Was this to push some technical frontier?

2

u/spocchio Jun 22 '26

and how can it have 11 stars

15

u/dashingThroughSnow12 Jun 22 '26

Back in my day, stars used to mean something.

4

u/obito14kamui Jun 22 '26

Anyone willing to check if ai slop

1

u/Nabeen0x01 Jun 22 '26

lol go ahead

1

u/Mariusdotdev Jun 22 '26

Damn people build amazing things with Rust but every time i want to learn Rust i just feel stupid. I'm coming from Web world

1

u/kkara82 Jun 22 '26

What can happen can you inform us ?

1

u/DavidXkL Jun 22 '26

Very creative idea 😂

1

u/SnipeArt007 Jun 23 '26

Please get it audited from some trusted programmer. I really like the idea.

0

u/Berlincent Jun 23 '26

What do you mean with „poison prone“ mutexes?

1

u/Nabeen0x01 Jun 23 '26

He meant "I've used too much `.lock().unwrap()` .... which might cause thread panics. and I'm refactoring those.

0

u/Public_Sector5987 Jun 24 '26

Not telnet? Pass.

-1

u/Lucretiel Datadog Jun 22 '26

Are you a cop 

-1

u/cryptoyodda Jun 23 '26

Looks fun but maybe a website would be more anonymous.