5 ms·
Show HN: Warp – Secure and simple terminal sharing
- joeyh 9y agoI recently built https://debug-me.branchable.com/ https://debug-me.branchable.com/ which also does quick and easy terminal sharing, but with the addition of a cryptographically secure proof of what was done in the session, rooted at the gpg key of the person who connected to it.
- ecma 9y agoJust say that it's a signed log of the session. "Cryptographic proof" isn't necessarily incorrect but it has other connotations which don't make any sense here and make it sound like it's doing something it's not (think cryptanalysis or ZKPs).
- siliconc0w 9y agoCool tool but in the Readme you should probably explain a little bit 'how it works' rather than just 'how to work it'. In this case, I imagine it needs to connect to and trust some outside coordinating service run/owned by someone (you?).
- vultour 9y agoBoth the client and the server (warpd) seem to be in the repo. I agree there should be an explanation early in the readme because when I came to the part with IDs I immediately went 'wtf? does this go through their servers?'. Edit: Reading through some of the replies here it might actually be using their servers at least for the ID resolution.
- efficax 9y agoI agree. This tool is pretty cool but I was a bit confused about how it could work since it just "worked" without prompting for a server. Looking at netstat it looks like warp connections are handled by connecting to an ec2 instance at ec2-35-162-152-151.us-west-2.compute.amazonaws.com, on port 4242.
- spolu 9y agoThanks! Great feedback. I'll make sure to make it clearer.
- tjoff 9y agoI really like that it goes against the current cancer we are experiencing on the internet. That is, * You don't need to rely or surrender to the cloud. * Neither you nor the clients need to create an account (or worse, require a google/facebook account).
- jdormit 9y ago> You don't need to rely or surrender to the cloud I would imagine that this goes through someone's server. It would be helpful if the readme gave a little more detail about how this works.
- city41 9y agoLooking at the source code suggests it is peer to peer. The code for daemon indicates you need to specify what address and port to listen on when starting up, and there is code about receiving incoming clients. https://github.com/spolu/warp/blob/master/daemon/cmd/warpd/main.go#L22 https://github.com/spolu/warp/blob/master/daemon/cmd/warpd/m...
- lilactown 9y agoThis is false. There has to be some way to resolve the name used (e.g. in the example, `warp connect goofy-dev` is used) to an IP address. Looking through the source code, I've found these lines: https://github.com/spolu/warp/blob/master/client/command/connect.go#L107 https://github.com/spolu/warp/blob/master/client/command/con... https://github.com/spolu/warp/blob/master/client/command/connect.go#L156 https://github.com/spolu/warp/blob/master/client/command/con... https://github.com/spolu/warp/blob/master/protocol.go#L13 https://github.com/spolu/warp/blob/master/protocol.go#L13 It looks like it defaults to connecting to `warp.link:4242`. I can't tell if it's routing the entire connection through warp.link or if it's just resolving the name to an IP address that then connect directly (I don't know Go very well).
- comboy 9y agoGiven that it's not explicit in the readme, not that easy to find in the code, and repeatedly posted to HN I would assume malicious intent and stay away from it. Assuming no malicious intent, not disclosing anything about it in the readme suggests not very security oriented mindset and therefore it's likely just not secure enough to use.
- confounded 9y agoWhy no explicit Linux support?
- ilaksh 9y agoIs this better than gotty?
- troydavis 9y agoHow many times is it reasonable to submit the same URL to HN? This link is to https://github.com/spolu/warp?attempt=8 https://github.com/spolu/warp?attempt=8. If one needs to add an "attempt" HTTP parameter to track submissions of the same URL, and this is the 8th attempt, that seems like way too many. Here's a few prior identical submissions by the same person: 1: https://news.ycombinator.com/item?id=14398392 https://news.ycombinator.com/item?id=14398392 (ie, https://github.com/spolu/warp?attempt=1 https://github.com/spolu/warp?attempt=1) 4: https://news.ycombinator.com/item?id=14407813 https://news.ycombinator.com/item?id=14407813 6: https://news.ycombinator.com/item?id=14452505 https://news.ycombinator.com/item?id=14452505 If 8 isn't too many, what is? 20? Submit the same link every day indefinitely until it reaches the front page?
- KenanSulayman 9y agoGiven that it is suddenly ranking high, I assume the ranking is arbitrary enough to warrant multiple attempts. Likewise, I'd like to see following topics of submissions so that I see this instead of many other, for me irrelevant, news and articles.
- derefr 9y agoIf something had enough inherent interestingness to end up at the #1 position (as this submission is right now), then I'd argue that its taking a number of attempts to do so is an indictment of the ranking algorithm for burying it before, rather than an indictment of the author for persisting. Certainly, if someone persists in trying and the thing just never gets popular, that's just spam. But if "the right timing" was all that was needed to cause the sumission to hit #1? Maybe "the right timing" needs to be a concept built into the submission queue.
- troydavis 9y agoIt's an interesting question. I could see it being a mix of that and a poor-quality ranking algorithm, so that it's too easy for articles to end up buried. Most examples of this are one person submitting daily articles from their own site or sites they're paid to market. Sometimes even those end up near the top of the front page, and often when that happens, if one looks at prior submissions from that same person and site, the article that made the front page seems like it would do worse than prior articles. I could see all of this as an indicator that the ranking/voting doesn't do a great job of letting interesting stuff get a shot, nor of penalizing folks who constantly submit posts on their own site (for months - different than this situation). The "New" page is easy enough to ignore that I could imagine few visitors looking at it regularly, so the profile of visitors to that page is different than to the home page.
- dakra 9y agoAnother good open source terminal sharing service is https://tmate.io/ https://tmate.io/ This gives you 2 ssh addresses (read only and read write) that you can send out.
- SparkyMcUnicorn 9y agoI've been using https://www.teleconsole.com/ https://www.teleconsole.com/ from the team behind teleport. It has Linux, MacOS, FreeBSD, x86_64 and ARM7 support. This looks like a great project and I'll be keeping my eye on it, but there's no reason for me to switch to this and lose out on features. It's open source, and you can even set up your own proxy so you don't need to rely on gravitational's servers.
- sillysaurus3 9y agoIt's a bit rude to post alternatives in someone's Show HN without also giving ideas on how to improve their product (e.g. which features specifically would you be missing out on?) I guess it's not so much the posting of alternatives, but you're really selling that particular alternative. It'd be nice for Show HNs to be less cutthroat.
- SparkyMcUnicorn 9y agoThis wasn't a "Show HN" when I posted my comment. It changed after the fact. It does come of a bit like I'm selling it I guess, but I'm not affiliated. I'm all for alternatives and having a choice instead of a monopoly. Like I said, this project looks great.
- codezero 9y agoI've never heard this. I always find relevant alternatives in HN comments as helpful, allowing people to compare and contrast different features and functionality. I also don't see anything in the guidelines about this kind of thing, has a mod commented about it before?
- sillysaurus3 9y agoAgain, it wasn't about the posting of the alternative. It was the casual dismissal plus the lack of any useful feedback. This wasn't a Show HN when the comment was posted, though, so it's a moot point.
- m-j-fox 9y agoThe feature I'd suggest for any peer-to-peer application such as this is some kind of firewall punching. It generally requires a 3rd-party on the internet. To avoid running services for a low-bandwidth application like this, maybe it could tunnel through a public IRC server or other public chat system.
- ecma 9y agoCan someone explain the actual use of sharing a terminal with someone while not being in person with them (in which case they could just watch you and shotgun the keyboard?)? I can't imagine watching someone else's terminal session without them talking about what they're doing and why would be particularly informative or help with onboarding. Maybe it's just one of those things that work for some people and not others?
- detaro 9y agoPhone/skype, text chat, ...? (general screen-sharing software of course is an option, but often kind of a pain and if you really only want to share a terminal this might be faster and is by design limited to the terminal)
- viraptor 9y agoYou call them. You don't need to literally sit next to them to hear them.
- spolu 9y agoYes this is intended to be used with an audio link.
- fiatjaf 9y agoDoes it relate somehow to Joey Hess's debug-me[1]? [1]: https://joeyh.name/blog/entry/announcing_debug-me/ https://joeyh.name/blog/entry/announcing_debug-me/