7 ms·
Clever idea. Begs the question of why you would use http if you already have a bidirectional webRTC connection, but I guess it depends on the application.
by robertclaus 2y ago
Clever idea. Begs the question of why you would use http if you already have a bidirectional webRTC connection, but I guess it depends on the application.
- throwawaymaths 2y agoYou can securely serve a webpage from a server behind NAT without creating a VPN and without https certificated
- dlenski 2y agoI suppose the persistence of IPv4 has broken all of our brains, but with IPv6 you can just Not Have NAT, and just have normal end-to-end connectivity to any random box in your home from outside. (And yes, I do this. Works great.)
- ycombinatrix 2y agoThis supports UDP/unreliable data streams in the browser tho.
- throwawaymaths 2y agoThere's something nice about being anonymous behind a communal v4 gateway. Also can you get an tls cert for a ipv6 number address? Or are you punching through using only ssh or unencrypted stuff?
- dgl 2y ago> There's something nice about being anonymous behind a communal v4 gateway. IPv6 lets you do this -- nearly every client will use privacy addressing, so your (default) source address rotates daily. However you can still connect to the machine on its main (non-privacy protected) IPv6 address.
- _zoltan_ 2y agoYou miss the point: that /56 or /64 is still assigned to you, while a NAT gw might serve 1000s of people.
- chgs 2y agoThe /64 doesn’t change, it’s unique to your network. It’s broadly equivelent of the /32 you get. CGNat adds a layer of privacy that a public /32 (ipv4) or /64 (ipv6) doesn’t give.
- klabb3 2y agoTangentially, these “privacy” addresses are such an ipv6-ism of small theoretical value at the expense of extra complexity and noise. If ipv6 had been “ipv4 but now with 100% more bits”, I suspect we would have come a lot further in global deployments.
- immibis 2y agoIPv6 literally is that, plus a few pretty minor changes. SLAAC? Literally a hack that accidentally caught on because some vendor implemented it sooner than DHCPv6 for some reason. It was intended that everyone would use DHCP just like before. And that's the biggest difference from v4 other than the address format.
- klabb3 2y ago> plus a few pretty minor changes They might sound minor but in practice they violate assumptions that are really crucial for implementations. Everyone who deals with addresses must make decisions about how and what to do in face of these quirks. Another example is the zone identifier string. So how do you store them efficiently in memory or a db? Golang did a really clever thing with netip but the implementation was not easy. Oh well maybe we can always ignore and strip it? Maybe, depends on the use case. The point is going from exactly 32 bit to 128 bit + sometimes maybe a variable length string (max length, encoding, allowed chars?) is not a small change for something so important and ubiquitous as ip.
- hcfman 2y agoThere’s lots of ipv6 available. But it’s not everywhere yet
- concrete_head 2y agoWould you be willing to share a few details on how you do this. And how do you prevent someone spamming your devices or is the risk so low you don't care? Unfortunately most ISP's in my area don't dish out IPv6 addresses without ridiculous monthly charges. I hope one day it becomes more commonplace.
- ffsm8 2y ago> And how do you prevent someone spamming your devices or is the risk so low you don't care? That's the job of a firewall and is unchanged between ipv4 and IPv6. Theyre both equally vulnerable to denial of service attacks
- jeroenhd 2y ago> Unfortunately most ISP's in my area don't dish out IPv6 addresses without ridiculous monthly charges If you've got an IPv4 address that responds to ICMP, HE's https://tunnelbroker.net/ https://tunnelbroker.net/ offers free IPv6 ranges (a bunch of /64s and a /48) for free. You can configure a tunnel to work through many routers, but with some setup you could also have something like a Raspberry Pi announce itself as an IPv6 router. Sites like Netflix treat HE tunnels as VPNs, though, so if you run into weird playback errors, consider configuring your device's DNS server/network not to use IPv6 for that. As for your questions: > how you do this Open port 8888 to (prefix):abcd:ef01:2345:56, or whatever IP your device obtains, in your firewall. It's the same process as with IPv4, except you can use the same port on multiple devices. > And how do you prevent someone spamming your devices or is the risk so low you don't care? While some services have started scanning IPv6, a home network from a semi-competent ISP will contain _at least_ 2^64 IPv6 addresses. Scanning the entire IPv6 network is unfeasible for most automated scanners.
- justsomehnguy 2y agoThey need to find them first.
- immibis 2y agoYou just plug a device into your network. The device acquires an address. You can type that address into another device on the Internet to attempt a connection to your device. If your device is running a web server that allows access from the whole Internet, this brings up the home page. If you have a firewall, tell the firewall to enable connections to that web server from the whole internet. What do you mean by spamming? People are scanning the Internet the whole time to see what's there, and it isn't a threat unless you are doing something terribly insecure. Scanning IPv6 is impossible in practice anyway, due to the high number of available addresses.
- fulafel 2y agoThough WebRTC works great with IPv6 too. Then the use case would be running it on a server that has incoming connections firewalled.
- klabb3 2y agoIPv6 can get rid of NAT which is one of the most annoying hurdles. It unlocks the type of use case where technical people can host something from home for fun, although many can’t access it because both parties need ipv6. But if you set your sights higher and want to build true p2p apps for non-techies, or if you want “roaming” servers (say an FTP server on your laptop), there are more obstacles than NAT, in practice: - Opening up ports in both a residential router and sometimes the OS or 3p firewall. Most people don’t know what a port is. - DNS & certs which require a domain name and a fixed connection (if the peer moves around across networks, eg a laptop or phone, DNS is not responsive enough)
- dlenski 2y ago> IPv6 can get rid of NAT which is one of the most annoying hurdles. Right. > It unlocks the type of use case where technical people can host something from home for fun, although many can’t access it because both parties need ipv6. At this point, that's an obstacle, but at some future point hopefully IPv6 will hit a critical mass and network effects will take off because there'll be enough stuff that _doesn't work without IPv6_, so customers will demand it. > if you set your sights higher and want to build true p2p apps for non-techies Definitely. Restoring the universal endpoint-to-endpoint connectivity on the IP network overcomes a _major hurdle_, a hurdle that's so big and longstanding that people have come to just assume its existence and fear and removal… but it certainly doesn't solve all the problems. > or if you want “roaming” servers (say an FTP server on your laptop) https://en.wikipedia.org/wiki/Multipath_TCP https://en.wikipedia.org/wiki/Multipath_TCP will take a big dent out of this, I think. > - Opening up ports in both a residential router and sometimes the OS or 3p firewall. Most people don’t know what a port is. I mean, UPnP makes big improvements in this area, but a lot of devices stupidly don't handle it, or block it for alleged security reasons. Frustrating. > - DNS & certs which require a domain name and a fixed connection (if the peer moves around across networks, eg a laptop or phone, DNS is not responsive enough) There's no real reason why TLS clients _must_ only trust certs when they see that the CN or SAN matches the _domain name_ through which they looked up the IP address. I think that with a better issuing infrastructure and UX, a TOFU-based (https://en.wikipedia.org/wiki/Trust_on_first_use https://en.wikipedia.org/wiki/Trust_on_first_use) approach to self-signed certs for peer-to-peer services could be both comprehensible for non-techies and highly secure.
- dingi 2y agoI don't think that's possible without a jump server. If all peers are NATed, there is no way doing p2p without a jump server. WebRTC is a giant rabbit hole itself.
- evbogue 2y agoThis idea makes me want cjdns and/or yggdrasil over websockets.
- immibis 2y agoDon't you want static peering setup for them?
- ongy 2y agoProvide a server on-prem at the customer, but allow them a hybrid access to the system. Via cloud when necessary, "local" (by WebRTC) when possible. While we could just open a local port, using the cloud to arbitrate gives us a common product vision, and proper authN/authZ. Also allows us to pull the latency down to single digit milliseconds. The regional relays are double digit. When we use relays that aren't regional it's a couple hundred.