6 ms·
I've used wormhole once to move a 70 GB file. Couldn't possibly do that before. And yes, I know I used the bandwidth of the relay server, I donated to Debian im
by netsec_burn 2y ago
I've used wormhole once to move a 70 GB file. Couldn't possibly do that before. And yes, I know I used the bandwidth of the relay server, I donated to Debian immediately afterwards (they run the relay for the version in the apt package).
- teruakohatu 2y agoThe wormhole transit protocol will attempt to arrange a direct connection and avoid transferring data through the relay.
- bredren 2y agoIs there a switch to fail rather than fall back on relay?
- lotharrr 2y agoNot really.. the closest approximation would be if both sides set their `--transit-helper` to an unusable port like `tcp:localhost:9`. That would effectively remove the relay helpers from the negotiation list, leaving just the direct connection hints. But you can't currently force that from one side: if you do that, but the other side doesn't override it too, then you'll both include their relay hint in the list. Note that using the relay doesn't affect the security of the transfer: there's nothing the relay can do to violate your confidentiality (learn what you're sending) or integrity (cause you to receive something other than what the sender intended). The worst the relay can do is to prevent your transfer from happening entirely, or make it go slowly.
- lotharrr 2y ago(magic-wormhole author here) Thanks for making a donation! I run the relay server, but the Debian maintainer agreed to bake an alternate hostname into the packaged versions (a CNAME for the same address that the upstream git code uses), so we could change it easily if the cost ever got to be a burden. It hasn't been a problem so far, it moves 10-15 TB per month, but shares a bandwidth pool with other servers I'm renting anyways, so I've only ever had to pay an overage charge once. And TBH if someone made a donation to me, I'd just send it off to Debian anyways. Every once in a while, somebody moves half a terabyte through it, and then I think I should either move to a slower-but-flat-rate provider, or implement some better rate-limiting code, or finally implement the protocol extension where clients state up front how much data they're going to transfer, and the server can say no. But so far it's never climbed the priority ranking high enough to take action on. Thanks for using magic wormhole!
- pyrolistical 2y agoSeems like the only way to ensure wormhole to scale is to only to use relay server to setup direct connections. I know this requires one of the ends to be able to open ports or whatever but that should be baked into the wormhole setup.
- fullspectrumdev 2y agoMaybe hole punching or similar might be worth examining?
- password4321 2y ago> move to a slower-but-flat-rate provider As I'm sure you're aware: https://www.scaleway.com/en/stardust-instances/ https://www.scaleway.com/en/stardust-instances/ "up to 100Mbps" for $4/month
- lysace 2y ago32.4 TB for $4, or approximately 700 times cheaper than AWS. Neat.
- AtlasBarfed 2y agoIt took this far down in the comments to get to some inkling of the meat of this. It relys on some singular or small set of donated servers? NAT <-> NAT traversal is obviously the biggest motivator, since otherwise you just scp or rsync or sftp if you don't have the dual barrier. Is the relay server configurable? Seemed to be implied it is somewhat hardcoded.
- lotharrr 2y agoYes, it relies on two servers, both of which I run. All connections use the "mailbox server", to exchange short messages, which are used to do the cryptographic negotiation, and then trade instructions like "I want to send you a file, please tell me what IP addresses to try". Then, to send the bulk data, if the two sides can't establish a direct connection, they fall back to the "transit relay helper" server. You only need that one if both sides are behind NAT. The client has addresses for both servers baked in, so everything works out-of-the-box, but you can override either one with CLI args or environment variables. Both sides must use the same mailbox server. But they can use different transit relay helpers, since the helper's address just gets included in the "I want to send you a file" conversation. If I use `--transit-helper tcp:helperA.example.com:1234` and use use `--transit-helper tcp:helperB.example.com:1234`, then we'll both try all of: * my public IP addresses * your public IP addresses * helperA (after a short delay) * helperB (after a short delay) and the first one to negotiate successfully will get used. > since otherwise you just scp or rsync or sftp if you don't have the dual barrier True, but wormhole also means you don't have to set up pubkey ahead of time.
- samstave 2y agoCan you turn the magic wormhole into an API for receiving a JSON payload directly into your magic wormhole ontop of whatever youre running in a fastAPI to route that incoming wormhole listener?
- lotharrr 2y agoThere's a `wormhole send --text BLOB`, which doesn't bother with a bulk-data "transit" connection, and just drops a chunk of text on the receiving side's stdout. You can also import the wormhole library directly and use its API to run whatever protocol you want. That mode uses the same kinds of codes as the file-sending tool, but with a different "application ID" so they aren't competing for the same short code numbers. https://github.com/magic-wormhole/magic-wormhole/blob/master/docs/api.rst https://github.com/magic-wormhole/magic-wormhole/blob/master... has details.