Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Nobody needs another SSH client. We made one anyway.

13»

Comments

  • cloudblastcloudblast Member, Patron Provider

    A little video preview of the AI terminal, can be used for way more complex stuffs ofcourse.

    For me at least it's quite useful to manage large fleets, I create custom detailed prompts and then it can run it across X amount of servers for monitoring/reporting to me specific things without having to set up a monitoring bloatware into the servers.

  • forestforest Member

    @cloudblast said: We decided to make it open source so everyone can contribute opening a PR, review the code and decide weather or not to trust this client or not.

    Trust is not just about determining whether there's malicious code. Vibe-coded slop is infamous for its severe security vulnerabilities. Despite the fact that LLMs are good at finding bugs that humans write, it's terrible with discovering the bugs it creates itself.

  • emghemgh Member, Megathread Squad

    @cloudblast said:

    Why are you showing it off like a keylogger :D

    Thanked by 2wadhah forest
  • cloudblastcloudblast Member, Patron Provider

    @emgh said: Why are you showing it off like a keylogger

    Wym?

  • cloudblastcloudblast Member, Patron Provider

    @forest said: Trust is not just about determining whether there's malicious code. Vibe-coded slop is infamous for its severe security vulnerabilities. Despite the fact that LLMs are good at finding bugs that humans write, it's terrible with discovering the bugs it creates itself.

    That's true, as I said you need human thinking and a good architecture made by humans to create quality code. People like you that thinks that in few prompts you can create a terminal like this are just delusional.

    I mean if you have a bit of trained eye you can understand immediately if something is slopped or actually thoughtfully designed.

  • forestforest Member
    edited 8:26AM

    @cloudblast said: That's true, as I said you need human thinking and a good architecture made by humans to create quality code. People like you that thinks that in few prompts you can create a terminal like this are just delusional.

    For an actual SSH client, you need plenty of review. One person and Claude is not enough to create a secure SSH client.

    @cloudblast said: I mean if you have a bit of trained eye you can understand immediately if something is slopped or actually thoughtfully designed.

    Anyone can vibe-code an app that they feel is "above" the "other slop down there". Just because it's not bottom-of-the-barrel "gimme a terminal pls" in one prompt does not mean it's not slop.

  • atklatkl Member

    @cloudblast said:

    @atkl said:

    @cloudblast
    Nobody needs another SSH client. We made one anyway.

    Actually that is the reason why I discovered WindTerm: I was looking for another free, portable, modern UI, user friendly ssh client (SSH + SFTP + RDP + VNC + etc.) in one window, to manage several VPS and to not have to run PuTTY, WinSCP, etc.

    Exactly

    Yes but i think comments about AI soapiness and potential security risk are very relevant. I first checked github was still alive and noticed you have a lot of issues reported but only 4 pull requests and last WindTerm version was released in March 2025: this is the reason why I am not using it although it looks and feel very nice.

    I did not then bother translating those many issues created in asian languages.
    I just did it now (thank you Google Translate!) and apparently many think WindTerm is dead and are promoting they own app

  • cloudblastcloudblast Member, Patron Provider

    @forest said: For an actual SSH client, you need plenty of review. One person and Claude is not enough to create a secure SSH client.

    We just released it, ofcourse we don't stop the development here, it's gonna be a fully supported project and hopefully someone would want to contribute on the repo development as well

  • forestforest Member

    @cloudblast said:

    @forest said: For an actual SSH client, you need plenty of review. One person and Claude is not enough to create a secure SSH client.

    We just released it, ofcourse we don't stop the development here, it's gonna be a fully supported project and hopefully someone would want to contribute on the repo development as well

    So why advertise it as if it's a fairly-polished, secure application for people to try out and use rather than an early pre-alpha that is bound to have a number of fatal security bugs and is in need of careful testing in a safe environment?

  • cloudblastcloudblast Member, Patron Provider

    @forest said:

    @cloudblast said:

    @forest said: For an actual SSH client, you need plenty of review. One person and Claude is not enough to create a secure SSH client.

    We just released it, ofcourse we don't stop the development here, it's gonna be a fully supported project and hopefully someone would want to contribute on the repo development as well

    So why advertise it as if it's a fairly-polished, secure application for people to try out and use rather than an early pre-alpha that is bound to have a number of fatal security bugs and is in need of careful testing in a safe environment?

    No one said it's a perfect product man...

    Still waiting you to find a fatal security bug that Im not aware of

  • forestforest Member
    edited 8:46AM

    @cloudblast said: No one said it's a perfect product man...

    Think of it like coming up with a new medication in a home chemistry lab. Sure, it's cool. Sure, someone should do some analysis. Maybe it'll be the next penicillin, who knows? But you shouldn't go advertising it on TV just yet.

    People aren't harping on this due to a lack of perfection, that's simply not it. The issue isn't that it might not be perfect (nothing is), but that I see absolutely no disclaimers or warnings, when traditionally a new security product would have big, fat, bold warnings. Instead, it's written like it's intended to get people to find it useful so they use it (an issue for a project intended to do something securely), with no mention whatsoever being made of the potential issues or lack of an audit.

    @cloudblast said: Still waiting you to find a fatal security bug that Im not aware of

    Aaaand now it fits in the bag with all the other vibe-coded security projects. I was waiting for that to come out. :)

    I'll bail for now and leave behind some advice: Code does not become less secure after a security audit finds bugs. They were always there. Think about that for a moment, and think about on whom the onus of proof must be placed.

  • cloudblastcloudblast Member, Patron Provider

    @forest said:

    @cloudblast said: No one said it's a perfect product man...

    Think of it like coming up with a new medication in a home chemistry lab. Sure, it's cool. Sure, someone should do some analysis. Maybe it'll be the next penicillin, who knows? But you shouldn't go advertising it on TV just yet.

    People aren't harping on this due to a lack of perfection, that's simply not it. The issue isn't that it might not be perfect (nothing is), but that I see absolutely no disclaimers or warnings, when traditionally a new security product would have big, fat, bold warnings. Instead, it's written like it's intended to get people to find it useful so they use it, with no mention whatsoever being made of the potential issues or lack of an audit.

    @cloudblast said: Still waiting you to find a fatal security bug that Im not aware of

    Aaaand now it fits in the bag with all the other vibe-coded security projects. I was waiting for that to come out. :)

    With that, I'll bail for now and leave behind a bit of advice: Code does not become less secure after a security audit finds bugs.

    How can you even get so mad at an open source project but still be happy about closed source products that companies sell you for a fat 10$/month of which you have ZERO knowledge of how those are built.

    It's quite curious for me.

    Leave alone the fact that you are just assuming stuff without giving one fact, which is quite rude.

  • forestforest Member
    edited 8:53AM

    @cloudblast said: It's quite curious for me.

    The answer to that curious question is simple: I'm not happy with closed source products. In any domain where security is important, I prefer to stick with solid, audited, and open source codebases. For example, OpenSSH and tmux.

    @cloudblast said: Leave alone the fact that you are just assuming stuff without giving one fact, which is quite rude.

    See:

    @forest said: and think about on whom the onus of proof must be placed.

    Perhaps you and Claude write secure code the first time, so secure that even questioning implied claims of security would be offensive, but that is not something I've ever seen before.

    And if you are aware that there may be, and in fact likely are, serious security bugs, then ask yourself why you do not add a big fat disclaimer that the code is unaudited and has never seen even one hour of scrutiny from a professional.

    Take care.

  • cloudblastcloudblast Member, Patron Provider

    Maybe you like this stuff better @forest https://github.com/ZacharyZcR/termius-exporter

    If that's the type of software you like

Sign In or Register to comment.