7 ms·
This is huge. One of the last major missing features from Tailscale IMO. I maintain a list of tunneling solutions[0]. Personally, I think the future of p2p netw
by anderspitman 4y ago
This is huge. One of the last major missing features from Tailscale IMO. I maintain a list of tunneling solutions[0]. Personally, I think the future of p2p networking and selfhosting may be through tunneled, SNI-routed TLS connections (exactly what Tailscale just announced). It solves IP exhaustion, NAT, and IP privacy at the cost of an extra hop and no UDP.
The big question is going to be pricing. The current top player in this space is Cloudflare Tunnel, which is a loss-leader product that technically forbids selfhosting anything other than HTML sites.
Selfhosting media can use tons of bandwidth. Any service that doesn't charge per GB is incentivized to limit your speeds.
[0]: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling
- api 4y agoSo basically that would mean a cloudflare for P2P, though maintaining data privacy at least. It’s better than no P2P but IPv6 solves exhaustion and NAT without the performance hit or protocol limitations and with no extra third party intermediary in the way. BTW this maintains data privacy but you can still tell a whole whole lot from metadata. On the flip side it would prevent the kind of “griefing” with DDOS that happens every once in a while with self hosted and P2P things. It’s not that common unless you are engaging with certain communities but it is an inherent Internet architectural flaw that this kind of works around (at a cost).
- anderspitman 4y agoI envision something more decentralized than Cloudflare[0]. I think you could have local companies in every major city that would own a block of IP addresses and provide tunneling services with SNI routing for people in the same region. They can also provide more expensive services like DDoS protection and caching for popular sites or even on-demand when your mom blog goes viral. > It’s better than no P2P but IPv6 solves exhaustion and NAT without the performance hit or protocol limitations and with no extra third party intermediary in the way. I just don't see ISPs ever implementing IPv6 without governments forcing them to. It enables p2p which increases upload bandwidth requirements and cuts into their bottom line. And even if we get IPv6 you still need the ability to open firewall ports in a way the average user can understand. Not hard technically but that's another standard that everyone is going to have to agree on and implement. [0]: Which I know you can appreciate. "Decentralize until it hurts; centralize until it works" is still one of my mottoes.
- Spooky23 4y agoHave you used a smartphone? Most mobile networks are IPv6 enabled.
- anderspitman 4y agoI just tried turning off wifi on my phone. After googling what is my ip and pinging the IPv6 address from another IPv6 device, it doesn't work. Whether it's a firewall/NAT/whatever is irrelevant. IPv6 as deployed does not provide p2p. PS - typing the IPv6 address was super annoying and error prone compared to IPv4.
- api 4y agoYour mobile network is probably still V6 at the core. They're either giving you V4 at the endpoint or your phone is hiding V6 from you. Android or iOS? Apple stuff is V6 native now. Android's gonna be mixed. Depends on the carrier network though. I am on Spectrum (Verizon network) in Ohio and get V6 with CGN for V4. My wired ISP provides dual stack.
- anderspitman 4y agoCan you ping directly to your phone from another device, or access a webserver on it? That would be awesome.
- api 4y agoNever tried but I somehow doubt it. Standard issue UDP hole punching absolutely does work though. You still usually need hole punching with IPv6 if there's any kind of firewall in the way, but unlike IPv4 with NAT it's virtually 100% successful. Even if IPv6 NAT is deployed there's usually a 1:1 internal/external IP mapping making hole punching 100% successful.
- Spooky23 4y agoPhone data traffic is proxied or NATted for qos and other purposes, even with IPv6. It works better outbound than the old model though. I use iSH to get a Linux shell and with a mini Bluetooth keyboard I work on some hobby projects on the train from my iPhone.
- tjoff 4y ago> It solves IP exhaustion, NAT, and IP privacy at the cost of an extra hop and no UDP. That is awfully expensive for something ipv6 already solves minus the privacy part. I don't see how it can be considered "huge". A slight convenience maybe? Also, routing everything through a 3rd party is a massive downside.
- bradfitz 4y agoWe love IPv6 at Tailscale! It's just not pervasive yet, so we do what we gotta do.
- apitman 4y agoIPv6 the technology solves it, IPv6 as it exists in the real world does not. Even if we got 100% IPv6 adoption overnight, you would still not have a universally adopted API for punching holes through router firewalls for p2p applications.
- Spivak 4y agoYep, and such a thing would never be allowed anyway because what network administrator will look at “yes random client devices can punch holes in my network from the outside to your not very securely assigned address” and rightfully say nope. Here’s the attack: - You want to get to A - And you’re on a device B that has access to hole-punch-as-a-service but no direct access to A. Good network administrator / sysadmin! - Attack NDP (ie ARP spoofing but IPv6 flavored) to trick the firewall just for a moment that you’re A [1] and request the port be opened to your evil server C on the public internet. - Oops.
- anderspitman 4y agoYep, tunneling is way more secure than direct p2p. Especially if you run the service inside some sort of sandbox/container/VM which is possible on all major OSes these days.
- aidenn0 4y agoSSL?
- 0x6c6f6c 4y agoWhere do they say you can't host anything besides HTML sites? Their docs even showcase various use cases for Tunnels besides that
- anderspitman 4y agohttps://www.cloudflare.com/terms/#28-limitation-on-serving-non-html-content https://www.cloudflare.com/terms/#28-limitation-on-serving-n...
- tsujamin 4y agolooool so I’m literally working on something like funnel (built on their tsnet package) as I type except for generic TCP/UDP listeners. This explains so much of what I’ve seen added to their codebase recently
- lewisl9029 4y agoAgreed, this is awesome! I've been using Cloudflare Tunnel for local dev, but the fact that it seems to be coupled to their CDN product with no way to permanently turn off the CDN functionality has caused quite a few headaches lately (though it's possible to turn off temporarily using "Development Mode"). Would love to give this a try, though from the post it's not clear if we could use our own custom domains instead of the provided ts.net ones? This is a necessity for my use case where I need to be able to handle wildcard subdomains.
- systemvoltage 4y agoWhere do you see Cloudflare Tunnel T&C? Their help documentation seems to promote Tunnel/Access apps in every possible scenario: > Our connector, cloudflared, was designed to be lightweight and flexible enough to be effectively deployed on Raspberry Pi, your laptop or a server running your data center. Tunnel does not programmatically enforce any throughput limitations. > If you are hosting a Tunnel in GCP, AWS, or Azure you can view our deployment guides which are more prescriptive in assigning minimum system requirements. https://developers.cloudflare.com/cloudflare-one/connections/connect-apps/do-more-with-tunnels/hosting-requirements/ https://developers.cloudflare.com/cloudflare-one/connections...
- anderspitman 4y agoYeah it's actually a bit difficult to find on google: https://www.cloudflare.com/terms/#28-limitation-on-serving-non-html-content https://www.cloudflare.com/terms/#28-limitation-on-serving-n...