lmfao i just wrote a PoC for grabbing someone's ssh public key by establishing a connection from a browser session and using it to create an account/passwordless authentication for my service
works with any distro/terminal that registers an xdg-mime type for ssh:// urls, and my modified sshd turning ED25519 SHA256 fingerprints into a half assed DHKX with salt
from there on i can route all connections via i2p first and only then to my service's host so i dont have to care about user data because it's anonymized (besides the side channel attack that you can see who is currently using the anonymizing service...)