It's not really a matter of "insisting". Suppose you start writing an open SSH tool for BSD in 1999. What language do you choose?
Now that it's 2023 and OpenSSH in C is widely used, it's not as if it would be good if it were just abandoned (certainly not good from a security perspective). It makes sense for a team to continue maintaining it, right?
There probably is a better language for an open SSH client. It's not going to write itself, though. This is open source. The interested people need to get together and figure out how to do it.
It's just weird to me to imply the openssh people are doing something wrong when -- absent a time machine -- they clearly are not, and in fact are developing and maintaining a very valuable tool (probably aren't getting rich doing it, either).
Pascal?
For what it's worth "insisting on writing in C" for a large piece of software that's been a fundamental part of the secure internet for over 20 years now is just matter of momentum. We're talking having to redo the entire stack from the kernel to the drivers, ABI and up in a whole new programming language. It's being done, just keep in mind it's an enormous amount of work to get there.
The person lectured, "The time is ripe for a Rust rewrite." People who read that comment would believe the author to be a programmer.
I sometimes wish the rust foundation would hire someone who does for rust what Filippo Valsorda does for go.
I mean... Why not? I know roll your own crypto is bad, but _someone_ has to do it. Might as well be you! Do it in the open, get feedback, attract high skill people to contribute to it and... Tadam! Cool codebase!
I can't shake the feeling that making crypto as this magical thing people show ldnnot dream of is doing a disservice to us all.
The class of error in the article is impossible in Rust unless you explicitly choose to use unsafe.
The implication openssh has no seatbelts is very wrong.
OpenSSH's internal architecture was engineered for robustness, and has privilege separation and sandboxing.