francoismichel / francoismichel/ssh3

Concerns about security statements and naming

Open
#61 14 comments 13 reactions 0 assignees View on GitHub
documentation
Dominant language
Go
Stars
5k
Forks
118
PR merge metrics
No merged PRs in 30d

Description

As an interested security enthusiast analyzing SSH3, I wanted to raise some questions about certain security assertions made in the documentation, as well as use of the SSH3 name/branding before formal standardization:

In particular:

- Statements definitively calling SSH3 "safe" or claiming "strong security" seem premature for prototype software without extensive external cryptanalysis or review over longer time periods.

- Use of the "SSH3" name and branding could be seen as presumptuous before going through an IETF standardization process and achieving consensus in the SSH community.

To contribute constructively, I think it would be beneficial to:

- Have more cautious security messaging in the README reflecting SSH3's current experimental state. This can encourage assistance improving its responsible development. #59

- Use a more tentative naming convention prior to standardization. #60

I opened this issue not as criticism but as constructive feedback from a security advocate hoping to help SSH3 progress and evolve responsibly. By discussing areas for improvement, my aim is to respectfully facilitate community involvement advancing SSH3 in a credible, ethical way over time. Please let me know if any part of this feedback could be clarified further!

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the README sections containing the security claims and SSH3 branding, then review the related issues #59 and #60 and their discussion. Done means the documentation uses cautious security language and a more tentative naming approach, subject to the project's decision.

Written by the indexing model from the issue text.

Assessment

Domain
content, documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.