4 ms·
Looks interesting. What I understood: it is basically overlaying privacy and net neutrality on the internet. I am therefore restricted to communicating with o
by tornadofart 1y ago
Looks interesting.
What I understood: it is basically overlaying privacy and net neutrality on the internet.
I am therefore restricted to communicating with other users of mycoria and can't access "the whole Internet" via mycoria.
Am I correct?
What isn't clear for end users, IMO:
- What's the primary use case it was built for? Are there applications using it for chatting / exchanging data / whatever?
- what's the difference to similar projects like, say, yggdrasil?
- what's the difference to using a VPN?
- dhaavi 1y agoYes, the primary focus is connectivity within the network. You can use it for pretty much anything you would use a VPN for, but it is much easier to configure and secure by default with a built-in firewall. Only services you actively expose are reachable by others - by default nothing on your device can be accessed by others. In the future, it will also provide some amount of privacy on the network. I think the biggest user-facing difference is the ease of configuration (ie. none) - if Mycoria had proper installers.
- gspr 1y ago> You can use it for pretty much anything you would use a VPN for, but it is much easier to configure Ease of configuration is very much also a feature of the finest VPN software I've ever used, Wireguard.
- dhaavi 1y agoWireguard is absolutely great for its use case! Mycoria aims to interconnect participants. Eg. you and your friend all have their home server. Everyone wants to connect to their own server, but also to the server of their friends. All of this is super easy with Mycoria. Let a new friend install Mycoria, add them to your friends in the config and give them a URL for accessing. Voila! Also, Mycoria is an automatic mesh network, I think Wireguard requires a fixed set of peers you configure.
- gspr 1y agoYou certainly can add an remove peers from your Wireguard network on the fly. Granted, this is something you have to do yourself, not something Wireguard has automatic tooling for, so I guess that's a difference :)
- ignoramous 1y ago> Wireguard requires a fixed set of peers you configure Not really. One can add as many peers (though there's a artificial limit to just how many, I think) at runtime. It isn't fixed. Products like Tailscale couldn't be built otherwise.
- dhaavi 1y agoI understand what you mean. Yes, the technology can do that. I was thinking about the WireGuard as a software in itself.
- unixhero 1y agoI use Tailscale and just invite friends to connect to my various servers from the web interface.
- tornadofart 1y agoIsn't it a bit different? A VPN is used to create (the illusion of) privacy when accessing anything on the internet. But I can't access anything that's not connected to mycoria with it, can I? If I were to access something like Netflix, would I need something like a mycoria reverse proxy server for Netflix?
- dhaavi 1y agoYes, Mycoria is primarily about connections between network participants, eg. access your server at home without public IP, or a hybrid/fully remote team with a couple servers here and there. In an open mesh network, you still want privacy from the other network participants. Mycoria might have exit nodes similar to Tailscale in the future, but it won't be a fan-out multi-exit system like SPN, for example.
- tornadofart 1y agoSo 2 use-cases within grasp: Firms could replace their VPNs for remote work with mycoria and have better security and control. I could also set this up for my home network and access my (for example) NAS securely. For the use-case "I want to access a publicly available page anonymously", we still need a VPN / TOR.
- dhaavi 1y agoYes, that is a good distinction!
- Jarwain 1y agoTo be sure I understand, in that first usecases where a company is replacing their VPN with Mycoria, would access controls/restricting access to devices is all firewall based? That technically there's a network path to all the other devices on Mycoria just limited by firewall rules? What comes to mind to me analogously (more from my experiences than anything) is like a global tailnet that leans on firewalls to segment things? A cross between tor and a vpn is quite appropriate too
- WhyNotHugo 1y agoAll nodes on Mycoria end up in one huge network. The PN in VPN is for "private network", so I couldn't say this can do anything that a regular VPN can do. Any node on the network can find my node via mDNS discovery and access any services which I expose. Services need to be secured in the same way I'd do on the public Internet, and not in the same way I do on a trusted private network between a few trusted nodes. That said, I do believe this is useful in a lot of scenarios where a VPN might be too much work to set up. While one does need to ensure that all services do authentication, the encryption part is valuable, and this does ease exposing services from non-routable nodes with no consistent public IP.
- dhaavi 1y agoMycoria is secure by default: It has an integrated firewall that only allows access from explicitly defined addresses, or, optionally from anyone in the network. Also, multicast is completely disabled on Mycoria.