11 ms·
Iroh 1.0
- Kinrany 4mo agoI wonder if Iroh and Zenoh could/should be used together. The fundamental component of Iroh is p2p routing by key, and the main utility provided by Zenoh is message semantics. The two seem complementary.
- Imustaskforhelp 4mo agoZenoh seems interesting but can you please give me some use case where both Iroh + zenoh can be combined to achieve something more trivially (ie. without hassle) or the use-cases of this combination. I'd be curious to know more about their combined use-cases!
- Kinrany 4mo ago...that's what I'm asking :)
- j4cobgarby 4mo agoDoesn't it seem odd to have "Pricing" for a protocol that's meant to serve a similar function to IP addresses? Maybe I'm misunderstanding something.
- adammarples 4mo agoMaybe. It's offering "Customized hosting and monitoring for Iroh apps".
- Kinrany 4mo agoFrom the same pricing page, it's all additional services: observability, relay hosting, support engineers.
- dignifiedquire 4mo agoAs others have already mentioned, iroh the core library and protocol is fully open source. But to finance the development of it, we offer additional services to make it easier to deploy and run it, especially for larger or more specialized use caes.
- embedding-shape 4mo agoCongrats for the launch, seems to have matured a bunch and Iroh gotten a bunch of neat additions since I last looked! You even managed to get 1.0 out the door before go-ipfs / Kubo ;) > But to finance the development of it, we offer additional services to make it easier to deploy and run it, especially for larger or more specialized use caes. Interesting (and somewhat proven) idea to finance it, smart :) Did you guys started doing this already on a case-by-case basis and have some experience of it already, and if so what are the common things you typically help out with exactly? I'm just curious what sort of things a company who'd use a protocol like that might need help with, that they wouldn't have experience with in-house, since they're going down a P2P road already (assuming that, maybe maybe need help with greenfield projects)?
- dignifiedquire 4mo agowe have been doing this for a while now, you can find some of our highlights listed here https://www.iroh.computer/solutions https://www.iroh.computer/solutions
- rafram 4mo agoI think it would be clearer if you put the "Pricing" navbar link under "Services."
- noworriesnate 4mo agoI don't mind paying for a subscription, as long as I'm not also paying for the privilege of being locked in to a specific vendor. If I pay for a subscription and then your prices quadruple or something, what are my options? Can I self-host a relay? Do I lose features if I do so?
- TheDong 4mo agoThe equivalent for IP addresses to what they offer would be closer to running a BGP router or ISP, or generally contracting with network engineers for your data-center's networking. If you want to run an ISP or AS, believe me it will cost you a decent chunk of money.
- icedchai 4mo agoI've been running my own AS for years. You can get an ASN and IPv6 from a RIPE LIR for $200/year or less. Then you need a couple of VPSes that are BGP capable. You can get those for $20 month. Then you can tunnel traffic back to your location with a Wireguard tunnel or whatever you prefer. It's relatively cheap! I also have a legacy IPv4 block I'm routing, which doesn't cost me anything.
- apitman 4mo agoIs there no annual fee on all IPv4 blocks, or just legacy ones, which I'm assuming means blocks that haven't changed hands in a very long time?
- icedchai 4mo agoI registered this one back in the early 90's, predating the existence of ARIN. No fees only on legacy ones, assuming one has not signed a registration agreement. I assume, at some point, I will be forced into signing an agreement, but it's worked well so far.
- apitman 4mo agoAwesome thanks
- serf 4mo agotailscale syndrome. "we want to be infrastructure for people, and a business towards professionals." stuck between "we need cash to operate" and "we want to be a public good infrastructural system." , with the negative parts of a for-profit whisked away with "Well it's open source." it's a business concept i'm okayish with as long as the "Well it's open source." caveat doesn't come with a total bespoke and unusable code base to figure out.
- rklaehn 4mo agoTake a look yourself. Our code is as good as we can make it, and everything is modular and well documented. For example our QUIC implementation noq which underlies every iroh connection can also be used as a standalone QUIC impl that implements QUIC multipath. https://docs.rs/noq/latest/noq/ https://docs.rs/noq/latest/noq/ If we wanted to have "total bespoke and unusable code" we would have inlined all of this into the iroh repo to make it unusable.
- colinmarc 4mo agoNot affiliated, but I am a very happy user of Tailscale and a very happy user of Iroh; we use the latter in production at work. Tailscale is a great service that happens to be open source, but Iroh is clearly structured as a library that you can build into whatever you want.
- PLG88 4mo agofwiw, Tailscale happens to be mostly open source, not completely. Yes, I know Headscale exists, it does not implement all the Tailscale functions (not non-functional production type capabilities)
- w4der 4mo agoRustDesk has a similar business model and works fine for what it is, is there something particular about TailScale and Iroh that makes you think it will not work?
- Imustaskforhelp 4mo agoGood for Iroh to have libraries within different languages. I think that with Kotlin support, the creation of some android/multi-platform gui apps can be made easier if they want to use Iroh.
- Arqu 4mo agoThanks, we agree! We used to have bindings for while but the maintenance burden at that point was too high. Now that 1.0 guarantees everyone some stability and we feel confident in the library, we have enough room to properly support it.
- dignifiedquire 4mo agohey, I helped make this :) will try to answer questions where I can
- zelias 4mo agohow can i make it give me zen-inspired life advice?
- projektfu 4mo agoJasmine tea and a game of Pai Sho.
- Hugsbox 4mo agoI'd also like for it to prepare tea
- BetterThanSober 4mo ago418 I'm a teapot
- dignifiedquire 4mo agothe zen life advice will come if you use it long enough :)
- amatheus 4mo agoThis looks very interesting. I’m not sure I understand this, but it seems to me like it competes (or is in the same space as) both Tailscale and zeromq/nanomsg via the protocols? I think it would be nice to have a comparison page to make it easier to position it (I didn’t find one).
- matheus23 4mo agoWe keep thinking about ways to combine iroh + zeroMQ! I think these two could compose. (Not familiar with nanomsg myself) About tailscale: It's similar, but iroh is not a VPN, so it doesn't add a TUN interface. Instead, you'd build iroh directly into your application. Using iroh you can build a VPN, and there are projects that do so (iroh-lan/iroh-vpn are some hobbyist projects). The upside of building it into your application is that it doesn't need special permissions and is easy to ship to the user.
- genpfault 4mo agoC binding: [0] [0]: https://github.com/n0-computer/iroh-c-ffi https://github.com/n0-computer/iroh-c-ffi
- dignifiedquire 4mo agoWhich I just finished updating to 1.0. But it is currently lacking in breadth of API, so if you start using it let us know what you are missing. In the meantime https://github.com/n0-computer/iroh-ffi https://github.com/n0-computer/iroh-ffi has the other language bindings with a more comprehensive API
- convolvatron 4mo agoI should read the specs, but since it's such a foundational issue maybe someone who knows could respond briefly? the problem with a flat addressing space is that it requires every intermediate node to have state about every address, or perform a costly discovery mechanism for those it doesn't know about. is there a clever answer to this?
- matheus23 4mo agoThe secret is that iroh still uses IPs under the hood :) But with QUIC, your connections aren't bound to your four-tuple, your connection can migrate from e.g. WiFi to Cellular with only a small blip/hiccup. And with QUIC multipath, you can have multiple four-tuples "active" at the same time. iroh uses e.g. a "real" IP path mainly, with a websocket-based HTTPS path via relay servers as the backup (e.g. in case UDP is blocked).
- rklaehn 4mo agoWe have an answer, but it isn't really clever. We do have both built in and pluggable address lookup services. Our default enabled address lookup service is using DNS in a creative way, but we also have a service that is fully peer to peer and is using the mainline DHT, specifically the bep_0044 extension that allows you to store a tiny bit of arbitrary data for an Ed keypair that you control. https://www.bittorrent.org/beps/bep_0044.html https://www.bittorrent.org/beps/bep_0044.html https://pkarr.org https://pkarr.org Some custom transports such as TOR hidden services have a discovery system built in. In these cases we can just use the existing discovery system. See for example https://github.com/n0-computer/iroh-tor-transport https://github.com/n0-computer/iroh-tor-transport
- andy_xor_andrew 4mo agoThe "address lookup" strategy is really interesting, especially how it uses actual DNS: https://docs.iroh.computer/concepts/address-lookup https://docs.iroh.computer/concepts/address-lookup https://github.com/Nuhvi/pkarr/ https://github.com/Nuhvi/pkarr/
- rklaehn 4mo agoI am one of the iroh developers. A question that frequently comes up: when will iroh support webrtc, or BLE, or LoRa, or ... Iroh as of now supports only IPv4, IPv6 and relay transports out of the box. There is such a large variety of potentially interesting transports out there that we can't support all of them without turning the codebase into an unmaintainable maze of feature flags. But we have added the ability to implement custom transports. That way your transport implementation can live in a completely separate crate. Existing experimental custom transports include Tor, Nym and BLE. https://github.com/mcginty/iroh-ble-transport https://github.com/mcginty/iroh-ble-transport Here is how custom transports work under the hood: https://www.iroh.computer/blog/iroh-0-97-0-custom-transports-and-noq https://www.iroh.computer/blog/iroh-0-97-0-custom-transports...
- Bender 4mo agoWhat are the risks if any of running public relays? Is this similar in concept to running Tor Guard Nodes / Relays?
- Arqu 4mo agoAll the data is e2e encrypted and nothing is stored. The usual self hosting public things rules apply.
- rklaehn 4mo agoIf you run a public unauthenticated relay you act as a home relay for whoever has your relay configured in their relay map and is close in terms of latency. So you might get a lot of traffic. You can configure rate limiting, as we do on our public relays. The traffic is fully encrypted and can not be decrypted by the relay. The only information the relay has is what is necessary for it to function - the endpoint id and ip addresses of the endpoints that are connected to it at any given time, as well as endpoint pairings. You relay encrypted traffic with no egress to the open internet. So if you want to compare it with Tor, it would be like a tor guard/middle relay, not an exit node.
- Bender 4mo ago
- logankeenan 4mo agoIroh has been amazing to work with and the engineers are so nice in the discord channel. The pragmatic approach to making p2p just work has been easy to understand. Their YouTube channel has great content too. Congrats on v1! https://youtube.com/@n0computer https://youtube.com/@n0computer
- dignifiedquire 4mo agothank you!
- musicmatze 4mo agoShame they use discord though.
- logankeenan 4mo agoWhy’s that? What would be the alternative?
- commandersaki 4mo agoSo what has the reception been like with IETF?
- Arqu 4mo agoWere interacting with IETF on a number of projects and so far it's been going well :)
- rklaehn 4mo agoIroh is a project that combines existing IETF standards in an interesting way. For example we use raw public keys in TLS for the key exchange https://datatracker.ietf.org/doc/html/rfc7250 https://datatracker.ietf.org/doc/html/rfc7250 instead of coming up with our own key exchange scheme. Our QUIC implementation noq is a standards compliant QUIC implementation that in addition to RFC9000 also implements the QUIC multipath draft RFC. We try very hard not to invent new things unless absolutely necessary. In a few places we had to implement draft RFCs, QUIC multipath and QUIC NAT traversal. And there are some corners where we had to add our own extensions. But we try very hard to keep this to an absolute minimum.
- saberience 4mo agoThis page is basically useless in explaining what Iroh is or does and why I should care.
- bel8 4mo agoAs I see, it tries to explain. But as someone who's not a network specialist, I fail to see how this is not a glorified P2P DNS. Maybe this example helps: https://github.com/n0-computer/iroh#rust-library https://github.com/n0-computer/iroh#rust-library const ALPN: &[u8] = b"iroh-example/echo/0"; let endpoint = Endpoint::bind().await?; // Open a connection to the accepting endpoint let conn = endpoint.connect(addr, ALPN).await?; // Open a bidirectional QUIC stream let (mut send, mut recv) = conn.open_bi().await?; // Send some data to be echoed send.write_all(b"Hello, world!").await?; send.finish()?; // Receive the echo let response = recv.read_to_end(1000).await?; assert_eq!(&response, b"Hello, world!"); // As the side receiving the last application data - say goodbye conn.close(0u32.into(), b"bye!"); // Close the endpoint and all its connections endpoint.close().await;
- dignifiedquire 4mo agoI would love to see that P2P DNS you are talking about
- bel8 4mo agoPerhaps it doesn't exist because there's no real need.
- embedding-shape 4mo agoSuch is life when you choose to be introduced to something by a version update blogpost, instead of clicking in the top-left corner and reading the landing page.
- SubiculumCode 4mo agoDid we choose, or was that the link we were given that introduced us to it.
- WhereIsTheTruth 4mo agoLooking at the pricing page, how can this be the future, maybe the post was written in 1998
- astonex 4mo agoNot sure what the difference is between this and any regular P2P network?
- rklaehn 4mo agoA difference between iroh and many p2p networks is that we try to use existing IETF standards (QUIC, TLS) as much as possible instead of reinventing the wheel. An iroh connection is just a QUIC connection, using TLS and TLS ALPNs for protocol negotiation. If you look at an iroh connection using wireshark, it is just a QUIC connection. You can use all the existing tools, and a lot of things you learn when using iroh transfers to traditional QUIC connections and vice versa. Most iroh contributors come out of the p2p world, and you could say that we had a bit of abstraction fatigue after working on regular P2P networks for some years. We have also so far resisted the temptation to write a DHT, opting instead to use the biggest existing DHT, bittorrent mainline, for our p2p address lookup needs. Many traditional P2P networks come with their own implementation of a DHT for discovery. Note that there are some "regular p2p networks" that use iroh under the hood, e.g. holochain https://blog.holochain.org/dev-pulse-154-holochain-0-6-1-is-here-and-its-smooth-like-butter/ https://blog.holochain.org/dev-pulse-154-holochain-0-6-1-is-... as well as various p2p chat apps. https://blog.holochain.org/dev-pulse-154-holochain-0-6-1-is-here-and-its-smooth-like-butter/ https://blog.holochain.org/dev-pulse-154-holochain-0-6-1-is-...
- weavejester 4mo agoForgive me if this is an ignorant question, but does your use of the Mainline DHT mean that Bittorrent clients will be responding to P2P address lookups from Iroh?
- rklaehn 4mo agoFirst of all: the p2p address lookup is an optional feature. You have to explicitly enable it. Mainline is incredibly frugal in terms of resource use, but we want it disabled by default so mobile apps don't look like bittorrent clients and get flagged by the OS. When we do a p2p address lookup, every mainline server node could possibly be responding. Any bep_0044 record gets stored on 20 random mainline server nodes. So a bittorrent client that participates in the DHT as a server and is long running enough to be included into the DHT routing tables will respond, yes.
- Seattle3503 4mo agoWhat are people building with Iroh?
- Arqu 4mo agoBy far not a complete list but a starting point https://github.com/n0-computer/awesome-iroh/ https://github.com/n0-computer/awesome-iroh/ Also you can join our discord and there's #showcase https://iroh.computer/discord https://iroh.computer/discord
- karissa 4mo agoSee https://www.iroh.computer https://www.iroh.computer and "use cases" at the top of the page
- mnutt 4mo agoI have been playing around with building an Iroh Tunnel Sandstorm app that can connect two Sandstorm instances, and share some capabilities exposed from one Sandstorm instance to the other, as if the capabilities were local. Iroh has been very reliable throughout the process.
- tumdum_ 4mo agoHow is that different from https://yggdrasil-network.github.io https://yggdrasil-network.github.io ?
- ben-schaaf 4mo agoNot an expert but this is how I understand it. Yggdrasil is a P2P mesh network. You configure peers to join the network and your computer becomes a relay node for everyone else to use. It doesn't work behind a NAT without port forwarding. Iroh is kinda just a connection protocol. If you get given a public key for another computer, you can establish a connection. Like you would an IP address. The magic is in being able to establish that connection regardless of where either device is, and keeping that connection alive through changing network conditions.
- 28304283409234 4mo agoI love it. I think. But I find it hard to parse tech videos with music in the background.
- Thaxll 4mo agoI don't understand the problem its trying to solve in the first place, IP works just fine, such as DNS. There is already IPv6 and quic, you need vendor and major software to have any traction in that field.
- Arqu 4mo agoEstablishing direct connections on the other hand is a much harder problem with the current internet infrastructure.
- huflungdung 4mo ago[dead]
- Kevcmk 4mo agoI'm not affiliated with Iroh or even using it, but... "IP works just fine". What!? This is _not_ a solved problem
- PantaloonFlames 4mo agoI think that was the question: What is the problem it is solving ? You’ve asserted “THIS is not a solved problem,” which suggests everyone is clear on what THIS means. I think that is not a good assumption.
- shevy-java 4mo agoBut what is the actual problem?
- duped 4mo agoEstablishing fast/secure P2P connections between computers.
- khowells 4mo agoEstablishing fast/secure P2P connections between ~computers~ *apps. If you want to connect 2 computers use Tailscale. If you want to write an app which offers peer to peer connection for some feature, then use iroh.
- MostlyStable 4mo agoI'm out of my technical depth here, but out of curiosity: is this meant to be a full replacement for the current IP address paradigm, or is this meant to be a specific tool on top of/alongside IP addresses that solves particular problems/frictions?
- Arqu 4mo agoA little bit of both. Natively it relies on QUIC and leverages existing IP infrastructure, however it also works with custom transports just as fine so you can interact via bluetooth for example.
- rklaehn 4mo agoI would say it is not a replacement but an addition. IP isn't going anywhere any time soon, but we add two capabilities on top. The ability to dial an endpoint by key, and the ability to get direct connections whenever possible. That being said, if some other technology becomes popular that actually replaces the IP address paradigm, iroh is well positioned to make use of it. From the point of view of an iroh application developer nothing would change. You still dial by key, and iroh will just make sure under the hood to get you the best possible connection, IP or otherwise.
- kamranjon 4mo agoTo me this sounds like tailscale - does anyone have any insight into how what this is doing is similar or different?
- hazkoulia 4mo agoMy 5 second summary: Tailscale connects devices and Iroh connects applications.
- forsalebypwner 4mo agoTheir use of addressing by keys instead of by IPs seems to be the main differentiator. Also the support for custom transports (BLE, LoRa, Tor) which appears to be in progress and not yet fully implemented. I love Tailscale, it's deployed on all my devices. But I might check this out for the transports part in particular.
- RationPhantoms 4mo agoTailscale uses MagicDNS which allows one to auto-generate a semi-memorable private hostname as well. I'm in the networking industry so I'm not seeing anything truly groundbreaking or that isn't offered elsewhere.
- forsalebypwner 4mo agoYeah and my understanding of Iroh wasn't quite right either, it sounds like it's positioned to be more of a library to use in code, rather than a VPN solution like Tailscale. I love MagicDNS - A long time ago I wrote a stupid Python script to have it continually generate MagicDNS names until one of them contained a word I was looking for.
- danudey 4mo agoThe pitch here appears to be that this can allow communication between services without having to add them to a tailnet or such; e.g. if you wanted to let a friend or coworker access some service on your local network without making them join a tailnet, add a public external endpoint to forward traffic, set up a VPN, etc. IIUC you just send someone 'here is the connection information' and it just works automatically.
- schlap 4mo agoWere all building the exact same shit.
- dignifiedquire 4mo agoare we?
- AgharaShyam 4mo agoLM studio recently released a mobile app powered by Tailscale -- https://lmstudio.ai/link https://lmstudio.ai/link . Iroh seems like a perfect OSS alternative for implementing similar p2p features.
- forsalebypwner 4mo agoTailscale is OSS AFAIK. Not their backend of course, but if you use Headscale then I believe every part is OSS.
- dignifiedquire 4mo agotailscale also is written in go, making the integration on mobile especially, often times a lot harder and more expensive
- jMyles 4mo agoSo is this like an unfree CJDNS? What are the main differences?
- rklaehn 4mo agoThere is nothing unfree about iroh. All core crates are published with the standard MIT and Apache2 licenses.
- jMyles 4mo agoOh gotcha - the 'pricing' page initially gave me the impression that routing was closed/paid. But I guess it's just hosted deployment?
- rklaehn 4mo agoYes, exactly. Our commercial offering provides more insight into your iroh deployment as well as a hosted relay network. At the enterprise tier you can also get priority access to our engineering team. Obviously we want to make people aware of these services. But we also have projects that use iroh at large scale without using iroh services.
- suwapat 4mo agoMissing a native go version
- rklaehn 4mo agoIroh is just a clever combination of existing standards such as QUIC with some draft RFCs and a tiny bit of clever custom logic added via TLS extensions. So in theory a go implementation is possible using a go QUIC implementation that supports the multipath extension. Our focus is the rust implementation, since it is very easy to use from compiled languages such as rust, C and C++ and to embed into languages such as js and python. But there are some other projects that attempt to provide a native go implementation: https://github.com/tmc/go-iroh https://github.com/tmc/go-iroh Edit: since iroh is just a library, it is also possible to link iroh into a go program. Linking a go program from other native languages is a bit of a pain, but linking a C or rust library into a go program is relatively straightforward and high performance.
- karissa 4mo agoWould you use it if there was a go version?
- ssx-x1 4mo agoreticullum is better, and faster
- konart 4mo agobetter and faster how?
- gamegod 4mo agoSounds good, but the first step in your quickstart is getting an API key, and I'm oh, so I guess your sales pitch was a lie and this is really just another Cloudflare-like play to build another intermediary in the internet. If that's not the case, then I shouldn't need an API key for hello world...
- rklaehn 4mo agoIf you are a rust developer, you can just take a look at the examples in the iroh repo itself or in our iroh-examples repo. None of them require an API key. https://github.com/n0-computer/iroh/tree/main/iroh/examples https://github.com/n0-computer/iroh/tree/main/iroh/examples https://github.com/n0-computer/iroh-examples https://github.com/n0-computer/iroh-examples
- jhbruhn 4mo agoThat to me looks like Reticulums [1] adressing ("Destinations") with transport done via QUIC. Does it add anything what Reticulum didn't already solve, other than using slightly different protocols - do they have an advantage? [1] https://reticulum.network/ https://reticulum.network/
- giloux314 4mo agoThis is the comment I was about to make. Reticulum is already a very complete network stack.
- nunobrito 4mo agoOr I2P that even comes with reinforced privacy: https://i2p.net/en/ https://i2p.net/en/
- forkerenok 4mo agoBesides the novel/different form of addressing Reticulum pretty much imposes its Zen on users. So in a lot of things where Reticulum is quite dogmatic, something like Iroh I'd assume (if it's reaching corporates) would provide more flexibility. I haven't checked out the source though. As an example, AFAIK, Reticulum encrypts packet origin, so only recipient can see them. I don't think this is admissible in a corporate network.
- r0l1 4mo agoNetbird offers the same. Just based on wireguard and everything is open source.
- rklaehn 4mo agoThere are some technical differences since we build on QUIC, not on wireguard. We think that QUIC offers some advantages for demanding use cases. But everything we do is open source as well. Everything in the core is MIT and Apache2 licensed, including the relay binary/library.
- colinmarc 4mo agoWe use Iroh in production at work, and I'm absolutely in love with it. I'd describe it primarily as "Tailscale-style hole punching as a rust crate", but of course you can sprinkle a lot of cool p2p stuff on top of the basic QUIC connections.
- deleted 4mo ago[deleted]
- dignifiedquire 4mo agothank you!
- kkapelon 4mo agoCongrats on shipping You need urgently a "versus" page that talks about tailscale/netbird/netmaker/zerotier/twingate/openziti Looking at the use cases, right now I don't see anything that cannot be done with Tailscale...
- dandanua 4mo agoNebula by Slack is also a decent player in this company.
- abricq 4mo ago[dead]
- geoctl 4mo agoHonestly I am happy that more remote access products are using QUIC, not WireGuard, for tunneling and realizing its technical benefits (e.g. AES hardware acceleration, dynamic endpoints, custom auth with JWT or mTLS, FIPS compliance, traffic masquerading as HTTP/3, etc.). I am a big fan of QUIC myself and I implemented it long ago in Octelium, which is a similar remote access product that's more centered around access control and zero trust rather than P2P connectivity. I believe QUIC should be the future of tunneling, especially when it comes to business and enterprise remote access use cases. Congrats on launching an I wish you the best of luck.
- basro 4mo agoI wish it had support for a system similar to webrtc's offer and answer SDP messages. From what I see, relay servers are doing a job that is equivalent to Stun + Turn + SignalingServer in WebRTC. This is great for simplicity, but having Stun Turn and Signaling live in the same server would make it harder to secure. For example, since in webrtc signaling is up to the user, it is most common to have signaling implemented as a web server, this allows you to have it behind cloudflare with the signaling server ip never exposed to the internet. If you are not interested in supporting turn, there is plenty of public Stun servers that can be used and Stun itself is a really cheap server to run. For iroh, it seems if I wanted to self host relay servers I'd be forced to expose their IP to the web which would make them really expensive to run if one wanted to make them DDoS proof.
- 0x59 4mo agoSo this could be used as a streamlined way for client devices (mobile phones for example) to phone home to servers (google.com for example) with user data and bypass some local network controls? (DNS block lists, for example) Is there an android SDK available?
- karissa 4mo agoYes there is an Android SDK: https://docs.iroh.computer/languages/kotlin https://docs.iroh.computer/languages/kotlin
- peddling-brink 4mo agoI’m thinking similarly. Seems delightful for malware development and exfil. But I haven’t confirmed how the actual connections are made.
- dangoodmanUT 4mo agoiroh is consistently one of the most delightful projects i've ever worked with. The people reflect that too. Congrats iroh team!
- nicebyte 4mo agoI am confused why this is needed. > IP addresses can break, without warning, and it's outside of your device's control. We have DNS? > Keys, however, are created & controlled by you. They stay the same as your device moves, and are yours to throw away, or not. So are domain names? This page does not do a good job of helping me find what it is that I'm missing.
- ben-schaaf 4mo agoYour phone and laptop don't have stable IPs, let alone DNS entries pointing to them.
- kkapelon 4mo agoThey do if you use tailscale and friends
- ben-schaaf 4mo agoEveryone I'd like to connect to isn't on my tailscale, nor do I want them to be.
- kkapelon 4mo agoThey don't need to be https://tailscale.com/docs/features/tailscale-funnel https://tailscale.com/docs/features/tailscale-funnel For this simple scenario (just exposing your laptop to a public IP) there are already a gazillion alternatives (e.g. ngrok)
- ben-schaaf 4mo agoFunneling means opening up the device for the entire internet to access, not just to those with my public key like in iroh. It's limited to 3 ports. It requires setup for each device. It's not peer-to-peer. It has throttled bandwidth. No, this does not do the same thing as iroh. Not even close.
- arilotter 4mo agoMy company was using Iroh for a production distributed ML training system & we LOVED it. The team was incredibly responsive even before we hooked up with an enterprise support contract, they're incredibly knowledgeable and the library itself worked amazingly. ++ to this lib. would use again over libp2p anytime.
- rklaehn 4mo agothank you!
- shevy-java 4mo ago> And because all data that comes from the connection is secured by that key, we can build up from that same key into identity, permissions, and attribution. So basically they want to find out who is who. In other words: sniffing. It's interesting how the discussion is currently shifting to meta-explain why sniffing is necessary. I noticed this at universities in the last years; people now either have a tablet or a smartphone or a yubico key. This will be extended in the future, there is no doubt about that. And they are selling it with fancy words, just as Iroh showed.
- porsager 4mo agoHow is this different from https://holepunch.to/ https://holepunch.to/ ?
- rklaehn 4mo agoHolepunch, formerly hypercore, formerly dat, is a great project. Their main language is js, which makes it difficult to embed into anything but js/ts applications. Also, they are very principled when it comes to peer to peer purity, whereas iroh is a bit more pragmatic. We use dedicated relays to faciliate hole punching, whereas holepunch tries to use other peers as a temporary relay for hole punching messages. Another difference is that holepunch have their own DHT, where we have a less decentralised address lookup service by default and use the mainline DHT as a fully p2p alternative. So TLDR if you are doing js in the browser, holepunch.to might be a good fit. If you work on native mobile apps or embedded devices, iroh will be better since it is pretty frugal. If you work with node.js, both will work. Just evaluate them both and use what works better for you. E.g. we support tiny embedded devices such as esp32. https://www.iroh.computer/blog/iroh-on-esp32 https://www.iroh.computer/blog/iroh-on-esp32
- porsager 4mo agoThank you so much for the great reply! Answered all my questions - will definitely look closer!
- gnarlouse 4mo agoIs the intent to replace the IP protocol ever?
- rklaehn 4mo agoNo. IP isn't going anywhere. The intent is to provide additional capabilities on top of IP. That being said, if IP ever gets replaced, your iroh based app will continue to work pretty much unchanged. Iroh will just get you the best possible connection (IP or whatever) under the hood.
- ramoz 4mo agoIve been prototyping with Iroh for awhile. I think this tech (modern p2p) represents what agent-to-agent (a2a) should be built on. Every agent should be reachable to each other without hosting itself as an http server. related prototypes https://github.com/eqtylab/agentbeam https://github.com/eqtylab/agentbeam https://github.com/eqtylab/real-a2a https://github.com/eqtylab/real-a2a
- mckirk 4mo ago_Every_ agent? I surely hope not. But it would be an interesting... artisocial experiment?
- ramoz 4mo agoI mean, I didn't mean specifically every agent, and I also did not mean as a experiment. I see real at scale uses for this. Agents operating on their own networks, cross-team agents, my own agents on my own laptop, etc. Sharing context only gets more important the better these things get.
- jbverschoor 4mo agoNice video production, but as you can see on this thread of nerds, the messaging is not clear.. Content first, presentation later.
- MoonWalk 4mo agoNot to mention that the title of the post doesn't even say what it is.
- rklaehn 4mo agoWe have plenty of very deep technical content on our blog, explaining features of QUIC such as 0-rtt, post-quantum key exchange, address validation tokens, embedded devices. A great thing about iroh is that due to it being just QUIC, when you learn about iroh you also learn about details of QUIC that are useful and transferrable for traditional p2p QUIC connections.
- jmward01 4mo agoI think I see the value prop here. Beyond its intended use, what about creating a full VPN out of it? This takes care of the hard part for a lot of home users, opening your vpn up in a safe way. I know this is solved by many other tools so this isn't a new thing but it may increase adoption. Is there already something like that? I imagine you have considered this and if it doesn't already exist have a good reason for not including it. If so, what is that reason?
- MoonWalk 4mo agoIs what?
- w10-1 4mo agoI definitely see the value! But I'm not confident I can tell whether there are e.g., security implications, and I couldn't find anything on point in the docs or on github (other than one discussion on authentication that mentions the information disclosed). Would love a whitepaper on that and any other issues adopters should consider.
- rklaehn 4mo agoWe should definitely do a better job explaining this. Regarding security, one thing to be aware of is that iroh connections are just standard QUIC connections secured using standard TLS with the (also standard) raw public keys in TLS extension. We don't roll our own crypto. What little non-standard crypto we had previously was removed on the path to iroh 1.0. So iroh connections are just as secure as the QUIC/TLS connections your browser makes to your banking app. Whenever there are some new concerns like for example post quantum security, we can benefit from industry standards. E.g. we do already support optional post quantum key exchange to secure connections. https://www.iroh.computer/blog/iroh-post-quantum-handshakes https://www.iroh.computer/blog/iroh-post-quantum-handshakes
- overgard 4mo agoThis sounds useful, but isn't this the problem that ipv6 is supposed to solve with 128bit addresses? (I'm not really familiar with why IPv6 never really seemed to take off -- does NAT block incoming IPv6 traffic? (I guess that's the other thing -- even though my devices all seem to have IPv6 addresses I can't recall ever using them))
- rklaehn 4mo agoIPV6 addresses are still addresses. They get assigned to your device, and change as you change networks. Iroh addresses are (currently Ed25519) keys. They are not scarce, so you can create them on demand and keep them as you move from one network to another. If IPv6 was everywhere I guess the hole punching feature of iroh would become less important, but the dial by key feature would remain just as important.
- tancop 4mo ago[dead]
- apitman 4mo agoIPv6 solves a lot of it, and maybe in another 20 years we can rely on it.
- janandonly 4mo agoThis is big > We built & continually check that iroh can compile to WASM & run in the browser
- yusefnapora 4mo ago[dead]
- wiremine 4mo agoThis looks really interesting... I think I grok the basic value prop. However, I'm confused on the open source vs. commercial offerings. How do they differ? How do they work together?
- flub 4mo agoiroh is an open source library. The relay servers are open source too but number0 runs public, rate limited, relay servers that can be used by everyone. The commercial offerings are for dedicated relay servers and more insight into your network.
- rklaehn 4mo agoThe core is open source and always will be. Crates are licensed the usual for rust: Apache2 and MIT. This also includes the relay servers. In addition we provide services that any commercial deployment using iroh will probably find essential: observability and a custom non rate limited relay network, as well as priority access to the engineering team.
- himata4113 4mo agoHmm, this really looks more of a relay network for sale, kinda like steam p2p. The only real use-case I see for this is for exactly that, connecting two or more players where one of the players is the host. Seems like it'll be a hard sell since steam is already so dominant and enterprise is dominated by tailscale... I see the proposal for being able to work with many different networks from different companies at the same time, but it's a pretty rare usecase and nothing some iptables can't solve. I can see the argument for chat in heavily censored regions of the world, but not sure if there's any advantages that iroh can offer over other solutions. Market fit will be hard to find, but best of luck.
- int0x29 4mo agoSteam sockets and CloudFlare's UDP forwarding really are different though. They provide ddos protection as well as route optimization due to lots of points of presence. Here there seems to be no mention of ddos mitigation or shorter routes due to infrastructure. Yes you need a key to connect but your iroh relay server can still be attacked. I suppose you could roll your own distributed anycast system for this.
- himata4113 4mo agoI assume that the 'enterprise' relays have ddos protection. DDoS protection also comes standard these days, but we've seen attacks go from 20gbps to 20tbps so if uptime is required then tough luck.
- Lapsa 4mo ago[dead]
- openscript 4mo agoWhat about censorship circumvention? Is there specialized DERP to DERP communication, that bridge over internet edge nodes doing DPI on QUIC?
- rklaehn 4mo agoWe do not use DERP. But yes, relay to relay communication is something we want to look into in the future for some use cases. As of now relays are completely self contained and pretty dumb. The protocol does not require relay to relay communication, which means that the relay code can be relatively simple.
- coldblues 4mo agoThe future of networking is decentralization. I'm a huge fan of Yggdrasil and I2P. We should just be able to buy a mini PC to run 24/7 and host whatever it is that we need on it and seamlessly connect to others. A lot of techies already have older spare machines laying around collecting dust that can become servers. It is far cheaper in the long run and easier to maintain than having to deal with domains and server hosting. I truly appreciate the work that the Iroh team puts out.
- tootie 4mo agoIt's been the future for at least 20 years now.
- coldblues 4mo agoThis post may be sarcastic, but some of us really have been living in the future so to speak, more than others. It's the nature of novel, groundbreaking tech. Adoption is not immediate.
- z3ratul163071 4mo ago[dead]
- edbaskerville 4mo agoHoping to use this to reboot an ancient abandoned project. At the time there wasn't a mature P2P connection layer that took care of all the realities of the modern Internet out of the box. Now there is, and it's great to see. This isn't Tailscale because it does secure P2P connections between any pair of devices, whether or not they have Tailscale. This enables real end-user P2P for, e.g., local-first apps with no server infrastructure except relays for resilience. And even if you lose the relay servers, things keep on working the same for any hosts that don't need them.
- miki123211 4mo agoI like the idea. A couple of questions: 1. How does Iroh handle key rotation / leakage? Could you build some kind of hot/cold system on top of it, where you'd have a cold "identity key" in airgapped, secure storage, used only to issue certificates for your hot "traffic acceptance" key? 2. Is there any kind of peer discovery / DHT, either built-in directly or through some semi-official higher-level protocol, like DNS for IP? 3. What about human-friendly peer names? Those are almost required for end-user friendly applications. Most solutions of that problem either assume that every single user is willing to dedicate their life to configuring DNS, rely on a trusted third party, or delegate the responsibility to a blockchain. 4. What are the channel reliability properties, and are they configurable? Can you decide how to handle out-of-order or lost packets, or does the protocol enforce a decision? If you're willing to tolerate loss, duplication and reordering, can you avoid head-of-line blocking? 5. Is peer anonymity a goal? 6. What about two mostly-offline peers who wish to communicate (think smartphone apps that can't be connected 24/7 due to battery concerns)? Overall, cool project.
- rklaehn 4mo ago1. Currently we are using Ed25519 keys. You could use our existing discovery services to add a level of indirection from a root key to the currently active key. It wouldn't be that much code, since the discovery services are pretty generic. But we haven't done so yet. 2. We have a centralized DNS based discovery mechanism enabled by default, and an optional bittorrent mainline DHT based discovery mechanism. We also have mDNS for local networks, and you can plug in your own. 3. Our current keys are non scarce but also not human readable. You can use another level of indirection via DNS or some blockchain based naming system like ENS to assign a human readable alias, but that is not built in. 4. Iroh streams are just QUIC streams, and reliable and ordered by default. There are APIs to receive data as it arrives, but this for really advanced users. Most users are best served by just using the streams as-is. https://docs.rs/noq/latest/noq/struct.RecvStream.html#method.into_unordered https://docs.rs/noq/latest/noq/struct.RecvStream.html#method... There is also an escape hatch if you don't want streams at all, e.g. if you have a consumer like a video codec that can deal with data loss themselves. We support QUIC unreliable datagrams ( https://datatracker.ietf.org/doc/html/rfc9221 https://datatracker.ietf.org/doc/html/rfc9221 ). https://docs.rs/noq/latest/noq/struct.Connection.html#method.read_datagram https://docs.rs/noq/latest/noq/struct.Connection.html#method... 5. Peer anonymity as in hiding the ip addr of a endpoint id can be achieved, but not with the default config. The default config is tuned for performance. You can hide your ip address by using one of the mixnet custom transports and disabling the ip transport. 6. Iroh is just connections. If a and b are never online at the same time they won't be able to communicate. You would have to write an iroh protocol that talks to some always online node. We do have some protocols that can be used to implement this, such as iroh docs, but that is not the main product.
- mrbluecoat 4mo agoSurprising you don't support golang
- rklaehn 4mo agoWe did have golang bindings in the past, but had to pause all bindings because keeping them up to date was not viable. Now that we have a stable API, we will revisit this. If there is enough serious demand we could publish go bindings. Iroh is a rust library that is very easy and efficient to embed into golang binaries.
- deleted 4mo ago[deleted]
- andrewflnr 4mo ago> Dial keys Maybe it's in the video I didn't watch, but I really think paragraph one should make clear what kind of keys and why. Cryptographic? Asymmetric? How do they do the job, at even the most basic level? It never explains, just dives into abstract claims of superiority and usage stats. I gather relays are involved; this would be a good thing to mention right away instead of making me sift it from the HN discussion.
- taf2 4mo agowhen i read "keys" i figured "names" like in my .ssh/config a named host that i access with a key... but listening more it sounds like a new way to do networking over QUIC...
- rklaehn 4mo agoAt the lowest level it is a creative way to leverage all the work the major cloud vendors have poured into QUIC for p2p connections. If you look at an iroh connection in wireshark it is just a QUIC connection. If you configure a SSLKEYLOGFILE so wireshark can actually look into the packets, you will see a few TLS extensions and somewhat unusual packets flying by during the handshake, but once established it is a completely normal QUIC connection. That is also why we are relatively confident regarding encryption security. It is just TLS. And we can also leverage new encryption like post quantum key exchange with just a few config changes, without any code changes. See https://www.iroh.computer/blog/iroh-post-quantum-handshakes https://www.iroh.computer/blog/iroh-post-quantum-handshakes One thing that is genuinely novel is that we use QUIC multipath to keep the different paths (relay, various direct IP paths) separate. This has some technical benefits because the congestion controller does not get irritated when the underlying transport changes. Each transport has its own congestion controller.
- morphism 4mo agoWhile the frontpage doesn't go in depth, the docs quickly do: First with https://docs.iroh.computer/what-is-iroh https://docs.iroh.computer/what-is-iroh and then following up with the how it works section. The docs are actually good from what I can see so far. From what questions you brought up so for it seems to answer them pretty quickly.
- born-jre 4mo agoAs a person which tried to love libp2p so much this look. Great will definitely take deeper look
- Kazik24 4mo agoI've been using iroh for a while now for personal projects. I wrote an utility for sharing locally running services with others: https://github.com/Kazik24/server_share https://github.com/Kazik24/server_share Glad I can finally update to 1.0. It's a great library.
- infogulch 4mo agoHow does Iroh's performance compare to wireguard?
- rklaehn 4mo agoI think we do very well with devices devices with limited bandwidth and changing connections. We are able to saturate a 1 GiB link from a normal desktop PC or good phone, but have some work to do to saturate a 10 GiB link with a single process. We don't have a comparison benchmark, but we are fast enough that we are not the limiting factor for many use cases. In many cases the performance bottleneck is the interface to the kernel to send and receive UDP packets. Our QUIC implementation is using all available tricks to make this as fast as possible. For example on OSX we use the sendmsg_x syscall to send multiple UDP packets in one syscall. On Linux we use GRO/GSO and recvmmsg to send/receive as many packets as possible. But to be completely honest, in some cases TCP is still faster for raw throughput on server class hardware. Decades of optimisation have gone into TCP. But QUIC/UDP is quickly catching up. All the major cloud vendors bet heavily on QUIC/UDP and are optimizing it. Since we just do p2p QUIC we benefit directly from all improvements in this area.
- infogulch 4mo agoI'm happy to hear you really care about perf. I might have assumed io_uring would be the high throughput kernel interface for Linux. Can iroh run on a proxy server which forwards requests to backends that don't integrate with iroh directly? What is the CPU overhead at link saturating speeds?
- rklaehn 4mo ago> I might have assumed io_uring would be the high throughput kernel interface for Linux. We might do an io_uring based linux only implementation at some point. For now we do care about performance very much, but also want to have a single code base for all supported architectures and platforms. We do support a lot out of the box, which is hard enough as is with a small team. And while io_uring is a bit better than the current sendmsg with GSO / recvmmsg with GRO setup, it isn't orders of magnitude. > Can iroh run on a proxy server which forwards requests to backends that don't integrate with iroh directly? We have a tool called dumbpipe that has options to forward local tcp services over an iroh pipe. Something like global netcat. And there are plenty of tools that do something similar for specific services, e.g. there is iroh-ssh. > What is the CPU overhead at link saturating speeds? We don't have exact measurements, but CPU is not the bottleneck usually.
- akavel 4mo agoHuge congrats on the release! I'm slowly trying to build an app on Iroh; it's progressing tiny bit by tiny bit, but I must admit I'm struggling a lot all the time, both with various low-level details, as well as with understanding many high-level aspects, concepts, and approaches. Oftentimes I have to resort to some LLM-generated "wiki" websites to help me progress. I really hope you'll manage one day to allocate some more resources to improve the docs. That said, when I manage to muster enough strength, I do manage to grind some progress, and also it's good to know the underlying tech seems robust, given how many real-world solutions you've built on it! At this moment, if I can try to ask one question: AFAIU Iroh emerged from an attempt at fixing IPFS. I also understand you've since focused more on providing the lower-level building blocks that would allow this and other solutions. Understanding some basics, but still having hard time to get a really solid grasp of the whole of Iroh, I wonder: between Iroh, p2panda, and Willow, what's available and what's missing / needs to be added if one wanted to try and build an "IPFS-like" with those technologies? I'm especially interested in an idea of a "new web" that would defuse DDoS of static websites in a Torrent-like way, forcing the downloading peers to also share their upstream bandwidth while doing this. I'm also thinking of e.g. a "globally-distributed Internet Archive", where I can easily download part of the Archive to my computer, and this automatically improves its availability on such "new web" for subsequent downloaders and browsers. Would you care to give a newbie something of a high-level overview of how one could try to do it over maybe some appropriate combination of Iroh+p2panda+Willow+DHT?
- rklaehn 4mo agoWe started as an IPFS implementation, but since then the scope of iroh has been reduced. Iroh is not IPFS, but more like libp2p. If you want something like a globally distributed internet archive you would have to use protocols on top of iroh. For example iroh-blobs provides verified streaming of content-addressed data using the BLAKE3 tree hash function. It is very close to itself being 1.0 (probably Q3), but for now it requires you to know from where to stream the data. What is missing to fully replace IPFS is a global distributed content discovery system. This is a really hard problem that IPFS itself never solved reliably in my opinion. I also still want this to happen eventually, but the first step is to get the connection layer super reliable and fast, which we have done. I wish you could also delegate this problem to the mainline DHT, but alas that is not possible because of some mainline limitiations. So I am working on the side on a new DHT, see https://www.iroh.computer/blog/lets-write-a-dht-1 https://www.iroh.computer/blog/lets-write-a-dht-1
- mcdermott 4mo ago"If the implementation is hard to explain, it's a bad idea." --Zen of Python
- virtualbluesky 4mo agoThis might sound pointed, but it truly isn't - why is this approach not already commonplace? As a concept, looking up a verifiable identity makes sense, but often ideas that made sense were looked into and discarded for valid reasons. Would be good to understand those to better understand when/when not to use the project?
- deleted 4mo ago[deleted]
- rklaehn 4mo agoPrevious similar attempts were often not pragmatic or frugal enough. They cared about peer to peer purity more than about it working under all circumstances. They also frequently overabstracted things. So we got into the sad situation that people associate peer to peer connectivity systems with having to frequently debug the entire stack and having recurrent performance or connectivity issues. A part of the motivation for the iroh team is to change this notion by being very pragmatic and minimalistic. E.g. the use of relays vs. enlisting other peers to help with hole punching.
- virtualbluesky 4mo agoWhat's the minimum viable number of relays if the entire internet was running on Iroh today?
- virtualbluesky 4mo agoAnd thanks for the reply, I like the philosophy of the bits I understand so far. Rare project in that sense, fwiw.
- lsp 4mo agoYou're right, it does make sense. This is how the internet was designed but not how it was implemented. Originally, every machine was a directly reachable peer, but a finite supply of addresses (IPv4) forced most devices behind translation boxes (NAT) that let them dial out without ever being dialable. Once traffic had to route through the few hosts that stayed reachable, those hosts became toll booths, which is partially where the more centralized internet we actually got came from. iroh basically patches the internet
- deleted 4mo ago[deleted]
- snowflaxxx 4mo ago[dead]
- yapancha 4mo agoMaybe it's just me but it's not clear immediately what this is about. I did get a sense after spending enough time. Just feedback.
- arianvanp 4mo agoAre you able to do any form of highly available loadbalancing with this?
- rklaehn 4mo agoWe have not implemented this yet, and there are some things to consider. But there is an open standard for load balancing QUIC connections, and we have hooks in our QUIC implementation noq to generate connection ids that should allow us to work with this open standard. https://datatracker.ietf.org/doc/draft-ietf-quic-load-balancers/ https://datatracker.ietf.org/doc/draft-ietf-quic-load-balanc... Get in touch if you have a demanding use case and want us to help.
- apitman 4mo agoIf you're new to Iroh, my mental model is roughly "Tailscale at the application layer instead of the network layer". If your question is, "why not just use Tailscale?", look at it from an app developer's perspective. If you want to release an app and have instances of your app be able to easily connect to each other, you could theoretically embeded Tailscale functionality into your app, but then the users of your app need Tailscale accounts, and your app is dependent on Tailscale. Iroh lets you embed this functionality directly, and provides public fallback relays. If your app gets too big for the public relays, using your own relays is the flip of a switch.
- bicepjai 4mo agoI understood more about what iroh does with this post then the video :) thanks for the mental model. Now how does iroh accomplish this. Great idea by the way.
- thejazzman 4mo agothis is how: https://docs.iroh.computer/concepts/relays https://docs.iroh.computer/concepts/relays
- gz5 4mo agothe closest comparison is openziti: + iroh and openziti can both be app-embedded + so the app developer embedding in their service is a good use case for both + openziti is used for services in which scale and security are critical + whereas iroh allows participation from parties which don't have any prior relationships - which can be very convenient
- embedding-shape 4mo ago> the closest comparison is openziti: Except without all the ceremony about setting up daemons, servers, controllers, "networks" and what not that openziti seems to have. Iroh is more "define protocol and hook two clients together" with everything in one binary. Unless I understand https://github.com/openziti/sdk-golang/blob/a6e5f1697a9dc34a41c1ed398d667b349f2b04b4/example/chat-p2p/setup.go https://github.com/openziti/sdk-golang/blob/a6e5f1697a9dc34a... wrong, it seems to require a "controller-url", is that controller embeddable as well?
- wartywhoa23 4mo agoHow soon till govporations require that people dial their services by key, issue and treat the keys like passports, and block those who say something against the grain, acess a forbidden site, read a forbidden book, happen to be of wrong nation or otherwise violate ToSes of said govporations? A wonderful chain to link to the CBDC shackle.
- bicepjai 4mo agoSo each app can be its own tailnet, and let devices talk to each other on its network using api keys. Like home appliances in HomeKit network ?
- YuanJiwei 4mo ago[dead]
- mnot 4mo agoThe site mentions preferring open standards in the IETF - where is it being discussed there?
- iand 4mo agoThe site is referring to Iroh's preference for using IETF standards rather than rolling their own.
- deleted 4mo ago[deleted]
- salgorithm 4mo agoI setup a TypeScript SDK with some examples to test in the browser. SDK https://github.com/SalvatoreT/iroh-ts https://github.com/SalvatoreT/iroh-ts Examples - https://salvatoret.github.io/iroh-ts/examples/chat/ https://salvatoret.github.io/iroh-ts/examples/chat/ - https://salvatoret.github.io/iroh-ts/examples/debug/ https://salvatoret.github.io/iroh-ts/examples/debug/ - https://salvatoret.github.io/iroh-ts/examples/poker/ https://salvatoret.github.io/iroh-ts/examples/poker/ I made this a while back because I want an easy way to throw together games for family game nights.
- sunshine-o 4mo agoI am looking at the awesome page [0] and was surprise not to see a syncthing equivalent. Wouldn't that an obvious use case? or am I missing a technical limitation? - [0] https://github.com/n0-computer/awesome-iroh#file-sharing https://github.com/n0-computer/awesome-iroh#file-sharing
- protocolture 4mo ago> IP addresses can break, without warning, and it's outside of your device's control. Keys, however, are created & controlled by you. This doesn't really make a lot of sense. Assuming this is true, its equally likely to be my gateway, or BGP peer IP that breaks. How Iroh offers anything in this scenario is beyond me. >The power of that key can't be overstated. We use it to secure the connection. And because all data that comes from the connection is secured by that key, we can build up from that same key into identity, permissions, and attribution. We can also use that same key as an address we can dial, no matter where it is in the world. It turns the internet into a secure localhost. This is a way better use case. This should be the headline.
- gorszon 4mo agoYeah, I agree, I had a hard time understanding what it is, because they wanted to define it in relation to IP, but this is not an IP replacement, this is just a different thing. Like a secure by design quic, or something, if I understand it correctly.
- bear330 4mo agoIt's very cool! I am planning add Iroh into my daily used https P2P tool (https://github.com/nuwainfo/ffl https://github.com/nuwainfo/ffl) which currently using WebRTC. It's very cool to support both protocols, but it seems like Iroh python support is via FFI which can't be used in my APE (Actual Portable Executable) build...thinking...
- superkuh 4mo agoI am happy to see that Iroh says they'll support the 1.0 protocol for the entire life of the project even if they make a new version. If they can stay true to this it'll be a useful alternative domain system. But using QUIC means it's CA TLS only. As we've seen with the US government pressure on Lets Encrypt recently this CA TLS requirement allows the US (or other nation's) feds to shut down your 'key' no matter where you are. If they allowed self signed or even plain text this would not be a serious issue. But QUIC libs generally can't do this or at best offer a 'scary' build flag for self-signed that is never enabled on any dev's machine during compiling for distribution.
- rklaehn 4mo agoWe are using QUIC, but using a QUIC/TLS extension called raw public keys in TLS. The DNS is not involved in any way, and there is no way anybody can shut down your usage of iroh. https://datatracker.ietf.org/doc/html/rfc7250 https://datatracker.ietf.org/doc/html/rfc7250 In the beginning of the project we did use self-signed certs, but due to raw public keys that is no longer necessary. And in any case scary build flags aren't an issue since we control our own rust QUIC implementation, noq.
- _carbyau_ 4mo agoSo, is there an open source variant of Signal using Iroh? IE could I get an app on my phone, to talk to anyone on the planet with that app directly without having to trust any middlemen like Apple, Google, WhatsApp etc? Could people have something like original facebook, but without Meta because of actual p2p?
- sgsvnk 4mo agoThis is great work, but the blog is too esoteric, likely written by the developers. You should revamp the website to appeal to more general software engineers with more easy to understand terminology to get better traction.
- Ingon 4mo agoAmazing, congrats on the release. I've been drawing a lot of inspiration from Iroh, while working on my own https://github.com/connet-dev/connet https://github.com/connet-dev/connet. While peers in connet communicate peer to peer, I have a long way to cover peer discovery and transparent connection migration. "Tailscale at the application layer, instead of the network layer" (as sibling comment describes it) is a great way of thinking about it. In my mind, with the right apps, Iroh (and connet) could really democratize secure self-hosting.
- aag 4mo agoFor a side project, I used Iroh to give my web server in the cloud the ability to print directly to my label printer at home. The API is simple and easy to use. It took no time to write a reliable system on top of Iroh.
- rklaehn 4mo agoVery cool project. I seriously wish one of the printer vendors would use iroh to come up with a network printing standard that just works. We constantly have issues with our printer. I have fewer issues with my bambu 3d printer than with my (also very expensive) epson inkjet. These people need to get their shit together, seriously. The way things are going we will have full AGI before we have working printers. If somebody want to do this, please reach out to us. We are eager to help. But this is one of the most annoying things ever with computers.
- comboy 4mo agoI'm so disappointed in this comment thread https://en.wikipedia.org/wiki/OSI_model https://en.wikipedia.org/wiki/OSI_model I've just learned about it, but my understanding is that Iroh is L7, compared to e.g. tailscale which is L3
- rklaehn 4mo agoThat is correct. Iroh connections are at L6, individual protocols such as blobs or gossip are at L7. From the OSI point of view, QUIC itself is a bit of a layering violation. It covers transport (L4, Reliable ordered delivery, stream multiplexing, congestion control, ...), session (L5, connection establishment and lifecycle, path migration, ...) and presentation (L6, encryption). And of course below that we have the ability to provide custom transports. This was done intentionally in QUIC to provide more control. The application layer doesn't have to care about what goes on below, but for some advanced use cases it can know what's going on and even influence which path is being used. QUIC/TLS being such a comprehensive and well tested package allows us to delegate a lot of the work and just add a tiny bit of logic to make it peer to peer. Although delegate is not exactly right, since we ended up having to write our own QUIC implementation, noq, to support QUIC multipath...
- Pbhaskal 4mo agobut does not quic internally needs an IP address to route , who maintain device vs ip address map. is it like torrent
- andai 4mo agoSee also: https://www.dumbpipe.dev/ https://www.dumbpipe.dev/ pipe over network using Iroh Also, for educational purposes, the first version was about 150 lines https://github.com/n0-computer/dumbpipe/commit/f64d4c3e772a21a53a60e7ac97cb2e4a9273b7a9 https://github.com/n0-computer/dumbpipe/commit/f64d4c3e772a2...
- BetterThanSober 4mo agoCorrect me if I'm wrong but assuming there is only Alice and Bob in the network, each with their key-as-address, and they are both behind a CGNAT, Iroh will still need a third party to host the relay?
- Landing7610 4mo agonot in this case, they have optional mDNS discovery
- rklaehn 4mo agoIf they are both behind the same CGNat, you can use mDNS to help them find each other. If they are behind different CGNat, you need a party that is reachable by both to help with hole punching and/or relay traffic. This is fundamental, there is nothing you can do about this. Some p2p protocols try to enlist other peers to be that third party. E.g. holepunch.to . Iroh uses dedicated relays for this. The relays can either be the n0 public relays, a n0 paid relay network, or self-hosted relays. No matter which option you choose, every iroh endpoint is able to talk to every other iroh endpoint unless they are fully airgapped from the internet.
- deleted 4mo ago[deleted]
- wngr 4mo agoKudos to the n0 team shipping 1.0! Truly exciting, stellar technical approach and execution; I hope you guys will get sufficient commercial traction to keep going!
- MayeulC 4mo agoShould I consider using Iroh for intranet communucation ? Is it a viable use-cases? The use-cases I have in mind is an app being deployed on a HPC cluster, onto many nodes, cut off from the internet. I had been looking at zeromq, but I very much agree with using keys rather than IPs where possible (after years of using yggdrasil, wireguard, tailscale, tor), so I am tempted to try Iroh. OTOH, this seems overkill if I'm using a client-server approach where the server IP is known.
- rklaehn 4mo agoWe have some customers that do use iroh inside data centers. You get the simplicity of being able to freely move nodes within the data center or even across data centers without having to reconfigure ip addresses. And once a connection is established the performance is comparable to a normal QUIC connection. Regarding client server architectures: I frequently build systems where you use p2p connections but have clearly defined client and server roles at the application level. Absolutely nothing wrong with that, in fact I think a big problem with existing p2p projects is that they try to be p2p at application level and overcomplicate things.
- terabytest 4mo agoAre there any good end-user apps that are supported on a broad set of platforms and use Iroh to support file transfers between e.g. Windows and iOS seamlessly?
- rklaehn 4mo agoWe wrote a small demo app called sendme to show off iroh. It is cli only, works on all operating systems that we use internally, and we frequently use it to send around qlog files: https://www.iroh.computer/sendme https://www.iroh.computer/sendme There are several projects inspired by sendme that use the same protocol but add mobile device support and a GUI: https://www.altsendme.com/en https://www.altsendme.com/en https://github.com/ARK-Builders/Drop-Desktop https://github.com/ARK-Builders/Drop-Desktop https://github.com/zignig/sendme-egui https://github.com/zignig/sendme-egui
- terabytest 4mo agoCool! But I'm curious why nobody's gone and published a complete app for multiple platforms? Seems like an obvious next step.
- deleted 4mo ago[deleted]
- logged4upvoting 4mo agoSo if i understand correctly is like Application 1 has a Ed25519 keypair Secret key private 3085c7405a88a968133e813e9f638a7d9b2e8088fe717ca535cc24d90b59815d EndpointID or public key, for connecting to you: 274d4c656f064d4c59fffe7db38d6bf90d63cb087d0b2afd2cfa534334f7071c and for connecting to App 2 you need to know the other endpoint id, no friendly "dnsish" name involved.
- rklaehn 4mo agoYes, exactly. Basically we chose the bottom edge of zooko's triangle. https://en.wikipedia.org/wiki/Zooko%27s_triangle https://en.wikipedia.org/wiki/Zooko%27s_triangle A mapping from a scarce but human readable name to a non-scarce but not human readable name would't be that hard, but we haven't done this yet. If we do it it will probably be an additional crate reusing some of our infrastructure, not built in to iroh itself. There are a lot of use cases where the non human readable names work perfectly fine. We would implement two versions, one using DNS and one using an appropriate decentralized system like ENS.
- shark1 4mo agoA relevant free and open source competitor: https://github.com/EasyTier/Easytier https://github.com/EasyTier/Easytier
- pacha3000 4mo agoThis is actualy interesting, thanks for sharing, but not really relevant as Easytier seems to be a tailscale alternative. Not a iroh alternative. Again, the difference is: tailscale/easytier/wireguard creates a VPN network on your computer/phone/whatever. So all apps can benefit of it iroh is a library . This is for developers who want to integrate this P2P routing logic inside their app. It is closer to bittorrent than it is to tailscale. Both approaches are great but fulfill completely different needs.
- mtndew4brkfst 4mo agoIroh is free-to-use, permissively licensed, relays are self-hostable, and it's all fully open source for all necessary components. The only proprietary thing n0 visibly has is a managed platform for private relays with SLAs and observability. Which is IMO a bog-standard business model, it's not open-core nonsense. T There's no billable metering of users, bytes, QUIC endpoints, etc.
- graphenus 4mo agoWow, for the first time this finally feels like the true web3.
- ghosty141 4mo agoWhat I don't get is, this makes it sound like applications can have peer to peer connections "on their own" but where does this actually work. If I have control over the whole device I might as well use a vpn, if I don't how do I ensure the firewall, network, etc. are all set up to allow the traffic necessary?
- rklaehn 4mo agoThat’s the beauty of it. The app end user doesn’t have to do anything. The iroh endpoint will determine its location in the world by probing the configured relays using QAD (similar to STUN). It will then choose a home relay and establish a https connection to it. When another iroh endpoint wants to talk they first briefly talk via that relay, then hole punch and establish a direct connection. All of this happens in the background without the user even noticing. It’s also very lightweight - runs on an embedded computer with 2 megabytes of RAM.
- 40four 4mo agoI’ve recently become somewhat obsessed with a couple of hobby projects that focus on local first, decentralized architecture that sync data between users p2p & that’s how I stumbled across Iroh. It really seems like a great project, and as far as I can tell, if you want to do anything with p2p in 2026 you’re going to hard pressed than to find a better option than Iroh. Really exciting to see a 1.0 release! Congrats to the team!
- Keyb0ardWarri0r 4mo agoCongrats! I think you should highlight more the IoT use case, It's a really great solution for devices that need to talk over multiple transports (Lora + IP) and to avoid the need for a VPN.
- rklaehn 4mo agoWe have made some progress reducing the set of patches that is needed to get iroh to run on an esp32 with SPIRAM. We just need a little dependency reduction for it to fit, but other than that iroh 1.0 works out of the box now.
- jessinra98 4mo agoCongrats on shipping
- pjrog 4mo ago[flagged]
- shynome 4mo agojust add nat is enough
- vivzkestrel 4mo ago- eli 5?
- croes 4mo agoSo browsers don't need fingerprinting anymore because each device has a unique key?
- wronex 4mo agoMe and my friend wanted git for a game project. Setting up a VPN for this felt overkill. Turns out git provides a very nice transport abstraction though. So I built an iroh transport for git. Now we can push directly to a shared repo running on an old computer behind NAT. All for free. https://github.com/wronex/iroh-git https://github.com/wronex/iroh-git
- vanous 4mo agoIt would be great if there were applications with support, like nextcloud and it's clients, client for talk and so on.