10 ms·
Show HN: Shellvault – Cloud SSH terminal accessible from any browser
- angerson 8y agoHey HN! Shellvault is a project I've been working hard on for a few months now. It's a cloud service that allows you to SSH from the comfort of any browser similar to Chrome Secure Shell, but with many more features. Shellvault is still young and I'd love to hear what you think about it. I put a lot of effort into encouraging best security practices both for our clients and on our own servers. I'll be here to respond to any questions or comments you have. Thanks!
- equalunique 8y agoVery cool. Have any plans to enhance mosh support?
- angerson 8y agoSure, what kind of enhancements do you have in mind? Mosh and regular SSH are both supported right now (you can choose which one to use on a per-server basis), but we haven't implemented any advanced toggles yet aside from setting the connection port.
- dpedu 8y agoThis look nice, amazing really. However, like others have pointed out, some people may be uncomfortable giving a 3rd party a doorway into their systems. Is a self-hosted version on the roadmap?
- sethammons 8y agoNeat looking service. From a security standpoint, it is a bit terrifying that it could be logging everything, no?
- angerson 8y agoThat's right. That's one of the big security considerations we've had in mind from the start, so we've provided a lot of documentation and notices about what we do and don't track [1] and how to use Shellvault while building strong security habits. We've done our best to be upfront about privacy throughout the site. We don't log any SSH usage details, ever. [1]: https://www.shellvault.io/policies/privacy-policy/ https://www.shellvault.io/policies/privacy-policy/
- dsr_ 8y ago"We've provided instructions on how to keep your servers safe in the events of a Shellvault data breach. We're not liable for compromised servers that result from not implementing these policies." Will you accept liability for compromised servers that result from a fault in your code, service or practices when the policies you recommend are implemented in accordance with your documentation?
- Mortiffer 8y agodid you-guys reuse any code from https://guacamole.apache.org/ https://guacamole.apache.org/ or all home grown ?
- angerson 8y agoShellvault was developed from scratch with Laravel and Vue.js (the terminal is XTerm.js [1]). One of our big design ideals while developing Shellvault was that setup should be just as easy as a standard SSH client, so there's nothing new you need to install server-side to use it. [1]: https://xtermjs.org/ https://xtermjs.org/
- Jnr 8y agoSorry but I have a trust issue with this kind of service. Saying that you don't log anything is one thing but believing it is something else. Even hosting this kind of web service on the server I try to access would be a "no" for me. But that would be a bit more acceptable for some use cases for other people.
- Khanhanhan 8y agoSame concern here. I use Google Cloud Shell in a browser to access GC servers but, since I'm accessing servers they control anyway, the trust isn't a problem. I have SSH clients on my computer and all mobile devices, so I'm not sure what I could use this for.
- angerson 8y agoRight, Shellvault isn't for everyone: we're aiming to provide a good service for anyone who wants more convenience than normal SSH can provide, and we've worked hard on transparently documenting security considerations and adding features that don't compromise on privacy. We've done a lot to try and work on trust, but that won't truly come without a good record of contented customers. Hopefully we can work hard and impress you!
- freakz 8y agoLooking good, you're right it's not for everyone but it will be the right solution for some, so don't get discourage from these mostly negative (rightly) comments. I see you comparatively to Serverpilot which is another server management for dummys type of service, they have made themselves a nice niche in the novice website admin community, which is where I see your service succeeding. Having said that one reason for the success of Serverpilot is that the founders had excellent reputation in the dev community as long time Microsofties, but browsing Shellvault I see no information who is behind the service. I have no idea who you are and that's what makes me hesitant about using your service. Some background info would help. BoL.
- angerson 8y ago
- Aeolun 8y agoTo be honest, I think I might almost consider using this if it were self-hosted, but even then it would be a fairly scary thing. Giving someone else control over my shell sessions just seems like a spectacularly bad idea (though I guess it’s no different when I use iTerm).
- jstanley 8y agoWhy is it no different when you use iTerm?
- Spivak 8y agoIsn't the 'self-hosted' version of this application your local SSH client plus an admin VPN? I think I would pay good money for that web client though, it looks very neat.
- Aeolun 8y agoIt’s all a matter of convenience :)
- wmf 8y agoFor a self-hosted alternative: https://guacamole.apache.org/ https://guacamole.apache.org/
- qmarchi 8y agoI think the biggest feedback item for me would be that most of the servers I access are on an internal network and firewalled off from external access. Which is not uncommon when you get into an enterprise setting (where this is useful) So, my suggestion is to-do one of two things: 1. Create a gateway service which makes an effective reverse proxy into the network. Wouldn't fully recommend this option as many enterprises will see this a a huge hole in their networks. 2. Create a version of this which can be deployed to the internal network, and not have any connection to the cloud instance. Business models for this would probably be per-user licenses, and probably the best idea if you want to bring in the big bucks™️.
- angerson 8y agoThanks for the feedback! This is something we've had in mind for a while, and we're hoping to get to work on enterprise support (including other features like key sharing between team users and usage auditing) after solidifying the platform for independent users. It'll be easier to add proxy support, but I agree that a possible opening like that isn't going to cut it. Another possible option is OAuth integration with cloud platforms like AWS or GCP, which more and more companies (including mine) are starting to use more often -- but they're still a minority compared to internal networks.
- bberenberg 8y agoSecurity page link is dead https://www.shellvault.io/documentation/security-best-practces https://www.shellvault.io/documentation/security-best-practc...
- angerson 8y agoYikes, that's a typo on the homepage. It'll be fixed in a few minutes once Cloudfront updates, thanks!
- jstanley 8y ago> Shellvault uses a websocket to connect a client-side terminal emulator to an SSH process on Shellvault's servers. When you type a command, it goes through the websocket to the SSH client running on our servers, and the socket sends the response back to the terminal in your browser. So this gives Shellvault complete shell access to your server. It could be improved by terminating SSH at the browser, and just using the Shellvault server as a dumb proxy. Step 1: javascript ssh client - https://github.com/mscdex/ssh2 https://github.com/mscdex/ssh2 Step 2: websocket tcp proxy - https://github.com/novnc/websockify https://github.com/novnc/websockify Step 3: javascript terminal emulator - https://github.com/rohanchandra/javascript-terminal https://github.com/rohanchandra/javascript-terminal Step 4: ??? Step 5: Profit EDIT: And a really roundabout way to do this is to run the dropbear ssh client inside Fabrice Bellard's in-browser Linux VM: https://bellard.org/jslinux/ https://bellard.org/jslinux/ which actually already works today
- angerson 8y agoTheoretically, yes (see our FAQ [1]), which is why we encourage careful usage. We don't log commands or usage. We actually looked at a browser-only implementation first. Sadly, there's a limitation on JS SSH: in-browser Javascript can't do SSH, presumably because it lacks the right security code. It needs system-level library support which isn't available except in Chrome's NaCL (which is how Chrome Secure Shell works). The stack you suggested here is a lot like how Shellvault already works, unless I'm missing something -- is there something about this stack that would let us stop being a middleman? It looks to me like the node SSH service would still have to be running somewhere, and our features are designed around being a cloud-only client (there are already lots of good deploy-it-yourself portals that we're not trying to compete with). [1]: https://www.shellvault.io/documentation/frequently-asked-questions/#can-shellvault-read-the-commands-i-send-are-they-logged- https://www.shellvault.io/documentation/frequently-asked-que...
- jstanley 8y agoThe point about the system I described is that you wouldn't be seeing any plaintext. It's a mistake that the ssh client requires node, I didn't know that. There's no fundamental reason you couldn't implement an in-browser ssh client the way I described, it's just more work than doing it the way you've done it.
- tytso 8y agoThis is described as "like Chrome Secure Shell", but the major difference is that with the Chrome Secure Shell application, the ssh client runs in the browser, so it's actually secure; where as Shellvault is an architected (by design) man-in-the-middle attack. Advice: if you can use Chrome Secure Shell, you should do so.
- angerson 8y agoOur goal is to provide a useful service for anyone who wants to be able to log in from anywhere, which does unfortunately mean we're stuck as a potential MitM. We wrote a lot of documentation about how to mitigate the security issues [1], but ultimately we encourage anyone with security on the mind to use their own SSH client. [1]: https://www.shellvault.io/documentation/security-best-practices/ https://www.shellvault.io/documentation/security-best-practi...
- flarco 8y agoNice. Here is an open-source, self-hosted option: https://github.com/paradoxxxzero/butterfly https://github.com/paradoxxxzero/butterfly
- z3t4 8y agoThis reminds me of Dropbox, but with the difference that Dropbox was for non-developers, whom does not know how to share files. Most developers already know how to use SSH, so what is the main selling point for this service !?
- angerson 8y agoThe big one is convenience: if you need to do some quick maintenance from a computer you're not usually using, it's fast and easy to do so here (e.g. if you want to administer your server from a firewalled work PC, or from your parents' house).
- tyingq 8y agoEveryone I've seen using something like this or Google cloud shell is doing it to get around oppressive corporate proxies to get some kind of work done. Proxies like Forcepoint/Websense are content-aware enough that simple tricks like having sshd listen on port 443 don't work.
- cdumler 8y agoI want to say first that I applaud you for the time and effort to build something. Getting of your duff and building something is awesome. That said, this product is a man-in-the-middle attack on SSH. You're a prime target for hackers. Expect to be hyper vigilant on everything have built, from your application to your website, since you're now owning the security for users.
- antoineMoPa 8y agoI would like something like this, but open source (my inspiration is codebox.io, which is dead). I might code it actually. My goal would be to have an easy editor, file manager and shell for Docker images that could be installed in one line of bash.
- forsakenharmony 8y agoI read codesandbox and was confused why it's dead But yes, it would be very nice if it was self hosted and doesn't seem too hard to implement (if you go for the minimum viable product, which is just a terminal), could even run in an docker container that ssh's into the host
- skywhopper 8y agoI can see how this might seem convenient, but using this service would be a really bad idea. The vendor even seems to know this: Sharing your public key is ok, but you should never share your private key (from the file id_rsa) with anyone. Instead, we've made it easy to create new Shellvault-specific keypairs. Unfortunately, this only means that Shellvault creates the private key itself. Which amounts to "sharing your private key". The lack of an end-to-end encryption tunnel means that despite the vendor's best intentions, this service introduces a lot of points at which a malicious actor (or accidental misconfiguration) could compromise your session. In short, there are multiple good, free, native, and local SSH clients and terminal emulators for every platform. Use those instead.
- deleted 8y ago[deleted]
- cntlzw 8y agoI don't want to be cynical. There is probably lots and lots of work being put in this project, but.... The business idea is basically this: hand me your credit card, I go to your favorite ATM, get some money and hand it to you. It is great service! Yes, a great service for some, but why would I give the most sensible credentials I own to a third-party? SSH tries to avoid man-in-the-middle attack. This is a man-in-the-middle attack as a service.
- vectorEQ 8y agoi do want to be cynical: sed -i -e 's/#Port 22/Port 443/g' /etc/ssh/sshd_config on a more serious note, as you described but maybe from a more grumpy person: i don't think it's a great service, as it just compromises credentials by default while a normal configuration could solve it. if the server is also hosting some https website, then put it on an alternate ipv6 address (they are free if not cheap) and ssh into that. you only need to edit 2 files on your server for that to work :s why pay 5$ a month if you already have a capable server you are paying for?? the promise of not storing credentials etc. is nice, but if your servers are compromised it will be childsplay for efarious people to intercept them even if you didn't design that aspect to happen in the service design.
- michaelmior 8y ago> a normal configuration could solve it Could you explain what you mean by this? I get not everyone wants this, but just making SSH listen on port 443 doesn't give you access on a computer without an SSH client.
- awill 8y agocorrect. You still need a client. The Op is probably referring to getting around firewall restrictions. Some companies block all outbound ports except p80 and p443, so if you work at such a company, you can't access your personal machine over p22. Shellvault lets you do that on p443. But so does changing your SSH server to listen on p443. A self hosted version of this might make a little more sense. However, it is still putting all your credentials in one place.
- null_content 8y agoPretty much any device these days can run some form of standalone SSH software or, worst case scenario, a shell + openssh (heck, even Windows can do that these days). Setting these up is fairly painless, and they are FAR more flexible than this solution, FAR more secure and the vast majority are open source - which is KINDA important when dealing with security. Sorry for being blunt, but all I see here is a huge gaping security hole. The $5/month is just adding insult to injury.
- joecot 8y agoYou can get something very similar using AWS Cloud9. You can make Cloud9 workspaces that are full IDEs, which also includes terminal access. If you use your Cloud9 workspace as just a frontend to you own server (using SSH), it's free (besides the likely negligible data transfer), and it can be any server you want, not just on AWS. If you use your Cloud9 workspace bundled to a new EC2 Server, you pay the normal hourly cost of the server, and can have it shut itself off when it's idle. So Cloud9 does the same thing, plus file editing in your browser, for pretty much free. And while Amazon isn't perfect, I trust their security more than a random site. https://aws.amazon.com/cloud9/ https://aws.amazon.com/cloud9/
- hsnewman 8y agoI use gotty https://github.com/yudai/gotty https://github.com/yudai/gotty, which works great.
- matthewaveryusa 8y agoThis is completely insecure sorry. A cautionary tale of how this works in reality if this product is successful is to look at hushmail, one of the first ultra-popular webmail sites that provided end-to-end encryption from Canada (via a java applet) -- they updated their terms and services after many years of running and fighting US court orders with this statement: "Hushmail is a web-based service, the software that performs the encryption either resides on or is delivered by our servers. That means that there is no guarantee that we will not be compelled, under a court order issued by the Supreme Court of British Columbia, Canada, to treat a user named in a court order differently, and compromise that user's privacy." https://www.wired.com/2007/11/hushmail-to-war/ https://www.wired.com/2007/11/hushmail-to-war/ To hushmails credit, they were making a protocol that was insecure by default a bit more secure. Shellvault is doing the opposite which is not commendable
- dzek69 8y agoI need to create account to test? No Thanks.
- angerson 8y agoYeah, sorry for the inconvenience. We added a registration requirement to prevent anyone from abusing the free trial so easily, although it would have been a nice idea to have a demo available.
- tptacek 8y ago1. This is very, very cool looking. 2. We would never in a million years sign off on any usage of this at any of our clients. I think there's something of pretty great value here, but am skeptical of the multitenant SAAS packaging it has now. No serious firm can reasonably hand off SSH access to a third party like this. Also: where's your security page? What verification work has been done on this?
- angerson 8y agoThank you for saying so. We've put a lot of work into just getting to this state, and next for us comes a lot more work on both features and security, like you said. Our focus right now is on independent users who are looking for convenience, since we can't expect to fully support larger groups who have extremely high standards that we can't yet meet. Edit: Apologies, I didn't intend to dismiss rightfully high security expectations as "extremely high standards". To put it another way, we have to start somewhere, and we've put plenty of work already into the basics, but our obvious next steps are to step up on security while also supporting users who are already willing to use Shellvault as-is. My above comment should have said that we don't yet have the resources to properly support enterprise-grade security concerns.
- wstuartcl 8y agoIt is hard to imaging that you interviewed any potential users of such a system before building it. You are solving a problem users do not have in a way that creates problems for users.
- shawkinaw 8y agoDismissing such basic security concerns as "extremely high standards" is quite off-putting. You need to earn a very, very high level of trust to successfully run such a service, as the other comments in this thread clearly show, and this comment does the opposite, at least for me.
- pugz 8y agoI'm planning on launching something similar-ish in the next couple of weeks, so your feedback would be tremendously appreciated. > I think there's something of pretty great value here What specifically do you think has great value? Is it the nice web-based UX? Something else?
- isatty 8y agoThis should not be a thing, I’m sorry. You’re selling an exploit as a paid service and I don’t even want to take the chance that a junior developer will fall for it. Literally no amount of documentation is going to justify having private keys to other people’s servers. One of the ways to fix it would be to open source ALL the code, let people self host it if they want to. You get to see your work live on atleast.
- maratb 8y agoWhat about using Google Cloud Shell (https://cloud.google.com/shell/docs/; https://cloud.google.com/shell/docs/; free, open to anyone with a Google account) as a jump host to your servers? Or using GCE's ssh-in-the-browser feature (https://cloud.google.com/compute/docs/ssh-in-browser https://cloud.google.com/compute/docs/ssh-in-browser) to connect to your own GCE VM (not free, in this case) and using it as jumphost? Both Cloud Shell and SSH-in-the-browser use an in-browser SSH client, so the connection is encrypted all the way and not MITMable. p.s. full disclosure: I work at Google on the team that maintains both of the above.
- dividuum 8y agoCloud shell allows Google to see what I type on the shell machine. So if I ssh from there into the target, nothing is gained and it's MITMable by Google. The only difference is that it's less likely to happen.
- maratb 8y agoThat's fair. Although there are pretty tight internal controls on what Google can do on your Cloud Shell, you have to put a certain level of trust into Google here. Getting your own GCE VM and using SSH-in-the-browser is arguably more secure. Last I checked an f1-micro VM would suffice and fits under the 'always free' GCE cap.
- dtrailin 8y agoAzure also has a similar feature (https://azure.microsoft.com/en-ca/features/cloud-shell/ https://azure.microsoft.com/en-ca/features/cloud-shell/) with built in VS code based IDE.
- shittyadmin 8y agoMaybe consider offering a self-hosted option - even if it's a paid one, it'd be a nice alternative to things like ajaxterm. I actually thought this looked great until I realized that it was a hosted service.
- brucemoose 8y agoNote to self: revoke ssh keys of users found to be using this.
- deleted 8y ago[deleted]
- letters90 8y agoYou could pay 5$ for this service. Or you could pay 5$ for a virtual server that can be secured off by yourself and still use reverse proxies on ssh to access any machine... Since a lot of people here have a technical background the most popular choice should be apparent.
- manishsharan 8y agoI use google cloud console which is also browser based ssh console. Its free with gooogle cloud account. I can then ssh to other servers. So this service makes no sense for me.
- alias_neo 8y agoThis feels like, some people that make cool apps decided to get into security, nothing I've read here makes me believe you really had a security hat on as you made this and that worries me. SSH is one of the most fundamentally critical pieces of a corporate infrastructure, the people I work with would absolutely not stop laughing if I told them this wasn't a joke. If you were selling an open source host-it yourself, support contract type model, I could totally see interest in this, but not a whole lot because if I have a device with a browser, there's a 99% chance it also has a terminal client/emulator. The next issue here is, you telling everyone you don't log anything is instantly a fail, because if its even _possible_, then it's not good enough. Saying you don't log anything doesn't matter because you can be compelled to, or you can be intercepted, MiTMd or just plain exploited. I don't see any value in another thing to pay for every month that by design _decreases_ your security; I already hate the everything as a service for personal use, no problem with it professionally, but SSH needs to keep moving forward not have gaping holes added in the middle. For personal use I have it solved with a VPN + terminal emulator, or it could be done with a VPS and some open source code. I'm sorry to be so blunt like other people here, but rather than see this fail I'd like to hope the chorus of opinions here would encourage you to rethink your model and actually make this something secure.
- andihow 8y agoThis is great for me because my job filters all ssh traffic that isnt within our WAN. I can remote into my homeserver using this now.