6 ms·
Rayfish, Peer-to-peer mesh VPN with no server to trust
- captain_dfx 3mo agoHi HN, we built Rayfish, a peer-to-peer mesh VPN written in Rust on top of iroh. The core idea: every node has a keypair, and its identity on the network is that public key. From the key we derive a stable IPv4 in 100.64.0.0/10 and a stable IPv6 in 200::/7, similar in spirit to yggdrasil. Those addresses are yours for as long as you hold the key, and they don't change when you move networks or your physical IP changes. You still reach peers by IP or by a name.ray DNS name, the difference is that the address comes from the identity rather than from where you happen to be. "No server to trust" is the part we care about most. There is no central control plane that brokers your traffic or holds the keys to your network. Peers find each other and connect directly over iroh's QUIC stack, with NAT traversal, hole punching, and relay fallback handled underneath. Relays, when used, only forward encrypted packets and never see your keys or decide who is in your network. Membership and trust live with the peers, not with us. How it works in practice: - Networks are closed by default. You join with a one-time invite, a reusable key for fleets of servers, or live approval from a member already inside. The room id is only for discovery, it is never an admission credential. - Any member can be granted the network key and act as a coordinator, so admitting new peers keeps working even if the original creator is offline. - There is a per-device firewall, directional and scoped by port and protocol, plus Magic DNS so you can reach nodes at name.ray (or just name, no need for the .ray suffix). - A "ray connect" flow links two people directly with no shared room, like a friend request between keys. - No ACLs. Networks are logical partitions. Firewall is per-host. You can combine both to have custom ACLs. It is a single binary with a daemon and a CLI. `ray up`, then `ray create` or `ray join <invite>`, and you have a private network. Honest limitations: it is early. The mesh protocol is gated at the transport layer, so we break compatibility between releases when we need to. There has been no third-party security audit yet. Mobile is not there. It runs on Linux and macOS today. Code: https://github.com/rayfish/rayfish https://github.com/rayfish/rayfish Happy to get into the addressing scheme, the iroh transport, the admission and coordinator model, or anything else.
- Retr0id 3mo agoWith IPv6 it's plausible that you can avoid collisions as long as you use an expensive hash function, but for v4 how do you avoid IP collisions? With only 22 bits of entropy in your v4 addresses, you'll get accidental collisions with only ~2000 users.
- dfish 3mo agoIndeed. So what we do is build your ipv4 using private key bits + collision_index. It is not perfect but it has worked in our tests. We'll keep improving it. The collision_index is incremented when a collision happens on a network. Let's say you join network A, B, C. But when you join C, another peer has the same IP. The coordinator (which is a role anybody can have in the network) will not accept you in the network unless you change your IP. Which means you need to increase your collision index. Now that process is repeated N times until you don't collide with any other peer.
- Retr0id 3mo agoSo I'd have a different IP on each network? (I really hope "private key" was a typo of "public key"?)
- dfish 3mo agoIndeed, it is a typo of `public key`. What I mean is that your identity is your private key. And no, you won't have a new IP per network. Your IP is `fnv1a(ip || index) when index > 0`. Which changes your IP in all of the networks. That's why we also implemented MagicDNS. You can just use your `user.ray` name. The daemon handles IP changes.
- Retr0id 3mo agoSo every time you join a new network, your IP in the others can change?
- someonebaggy 3mo agoI don't know why your post was autoflagged but what makes your product unique from the rest?
- dfish 3mo agoMy product is unique because it is not a product. Like it is mentioned in the article. I don't care about monetization, I just want a good trustless p2p vpn that anybody can use. In the future even normies will be able to. I am working on an android/ios app (ios not yet but in the future) to at least share my clipboard with my computer or send images. Which seems trivial but you dont have a really good (not battery consuming) solution for android<>macos. Anyway. Rayfish is p2p no central coordination needed. Other's do need some central coordinator. The main disadvantage one might find is that it uses iroh which is built on top of QUIC. Tailscale and others use wireguard, which is nice and compatible with legacy VPNs. Also they have a kernel driver which we dont. It's all userspace. I didn't want to reinvent the wheel.
- kamranjon 3mo agoThis is very cool - I will likely see if I can use it in place of tailscale for my local LLM hosting. I feel like not having that required login would be great. Also the direct connect feature seems pretty cool, since that’s usually all I need for my use case.
- whywhywhywhy 3mo agoHaving an install script that you paste into the terminal and all it does is download a binary and stick it in a folder is wild. If your users are savvy enough to be running random scripts they shouldn't need a script to do this and if they're not savvy enough to understand how to do that then the last thing they should be doing on earth is running a random terminal command off a website.
- atrettel 3mo agoI still have no comprehension of how curl piped into a shell command has become the default installation method for many projects (looking at you, Rust...). It breaks my brain as to how potentially unsafe it is.
- barnabee 3mo agoEveryone’s eventually going to run a binary they downloaded from the same place, if you’ve already decided to do that, why is a curled install script worse?
- yubblegum 3mo agoBecause it normalizes a practice that, while acceptable in context of a well known project with numerous dedicated eyeballs such as Rust language, is not a generally acceptable method of installing software.
- EGreg 3mo agoExactly this. The correct way is to have M of N signatures on specific package manager pinned versions. And you trust the auditors to look at each new version, of a well-known package. We should start a project and get it funded, to do just that. The money can go to LLM tokens for audits, at least, and hosting the multisigs and the package managers. Anyone want to partner on this? See my profile on HN and email me.
- deleted 3mo ago[deleted]
- Fabricio20 3mo agoOne thing I seem to struggle to understand is, a simple invite code system is showcased, but how does host Alice in one country know how to contact host Bob in another country with just the invite code? This seems to require a coordination server at least right, or does the invite embed some sort of information that'd allow Bob to directly reach Alice with just the invite code?
- utilize1808 3mo agoI think for this kind of system to work, there has to be SOME kind of public/shared server to do the coordination. If the inviting node is behind a firewall then no amount of information can enable a guest node to connect to it without a node reachable by both.
- tom1337890 3mo agoIroh or n0 seems to solve that. It's they're underlying network protocol. When you're behind some cgnat, iroh falls back to public iroh relays hosted by n0: https://docs.iroh.computer/concepts/relays#public-relays https://docs.iroh.computer/concepts/relays#public-relays However you could self host one of these on a public server you own. Then you're independent.
- polycancel 3mo agoSeems like nothing can really get around this without a server/relay/TUN/STUN server. Peer to Peer messaging just doesn't work otherwise. Saw Iroh post on HN. Just wonder how it differ from Nostr, Scuttlebutt or Yggdrasil or DHT etc? Many from Nostr claim that they are successor of scuttlebutt, but many devs from Scuttlebutt highly dispute that. Be good to get a comparison between these protocols for devs who want to use them.
- Groxx 3mo agoStable IP addresses solve it as well, but these kinds of things are not generally aimed at contexts where those are an option. Even IPv6 isn't generally stable - the prefix is ISP-defined and tends to vary similarly to IPv4 with CGNAT. There's also "dynamic DNS", which is basically just caching one side of that server/relay/TUN/STUN handshake, and relying on DNS for global discovery. For Iroh vs Scuttlebutt / DHT, I'll break that into two parts: 1) Iroh uses DHT for host discovery: https://docs.iroh.computer/about/faq#how-is-iroh-different-from-other-peer-to-peer-networks https://docs.iroh.computer/about/faq#how-is-iroh-different-f... , and Iroh is more about "use that DHT to get a usually-direct connection globally and then you can do whatever you want", while Scuttlebutt is strictly "... and use that connection to exchange append-only logs via gossip, to implement the Scuttlebutt protocol". (Iroh does have some first-party protocols you can use, but it's lower level in general) 2) Scuttlebutt isn't DHT-based, it's "connect to a known IP to get its data and discover connections" -> "connect to them and repeat..." -> "connect further..." -> etc, plus limited-hop feed replication by default. There isn't a global lookup to connect to any member or retrieve any data, it's all friend-of-a-friend connections and you can (and do) lose connection to someone if they get a new IP address and there's no F-o-a-F(-o-a-F(...)) replication route from them that reaches you (rare in practice since they likely re-connected to people they follow, which eventually trickles data through the mesh similarly to before). This is also part of the reason that it works instantly when you're on the same network as someone - it's less "it can work locally if you don't have internet access" and more "local is just a discovery method, the internet isn't special at all because it's all just direct connections". And as far as I understand Nostr, it's conceptually similar to Scuttlebutt, but with direct support for centralizing for performance (relays) and some degree of mutability / forgetfulness / etc. Scuttlebutt is a bit extreme about its logs being immutable and the only way to exchange data, and it's part of the reason it can have rather major perf issues (like needing to pull gigabytes of data before you can discover a feed's display name). (I say this as a fan of Scuttlebutt in principle, but not in practice - there are lots of practical issues with existing implementations that could be solved, but haven't, and it's a large part of why the ecosystem split into other protocols) It may also be worth pointing out that DHTs also need stable hosts to serve as initial bootstrappers, and apps that use them tend to hard-code a web URL where they can get a small list of those nodes. They just use them to discover other nodes, and save them for next time so the bootstrappers aren't constantly needed.
- Yoofie 3mo agoLooks like no support for Windows :(
- dfish 3mo agoNot yet. I'll support it in the future
- Avicebron 3mo ago> and membership is a signed record they each carry, not a question they ask a server. Sigh.. I like the project though. It looks very similar to something I vibed up recently, must be in the air
- winterqt 3mo agoWhat’s the sigh to, out of curiosity, just because this makes revocation hard?
- Borealid 3mo agoThe grandparent comment is correctly pointing out the sentence is an LLM tell. "Membership is a question they ask a server" is a bogus sentence. "membership" is not a "question". It's syntactically valid semantic nonsense. "Membership is dictated by a server" is one of several human sentences saying what that one is trying to.
- mintplant 3mo agoGoing from starting the project two weeks ago to already having a flashy marketing site is another tell, unfortunately. As much as I would love to see a trustworthy version of this idea. https://github.com/rayfish/rayfish/commit/c49816e6dfba19e91a8083d7fa42e84a3ba73066 https://github.com/rayfish/rayfish/commit/c49816e6dfba19e91a...
- dfish 3mo agoActually the flashy website was built 4 years ago by another person. We actually tried to build it 4 years ago, but other ventures with higher upside kept our focus. Now you get a VPN for free, no strings attached, although it is vibecoded you still complain :cry: If you dont like it dont use it
- Avicebron 3mo agoPartly. Partly because using EUF-CMA pins the record to the CA which makes membership deniability non-trivial which I don't love. It's not dumb, it's what Signal uses AFAIK and in transit message deniability is different than the signer. But still.. Also that sentence structure is very claudelike.
- ChocolateGod 3mo agoSo it's effectively a clone of Nebula minus the need for a lighthouse.
- skulk 3mo agoNot really. Nebula creates a layer-3 network[1]. Rayfish is built upon Iroh which is a layer-7 network. [1]: https://nebula.defined.net/docs/#technical-details https://nebula.defined.net/docs/#technical-details
- aftbit 3mo agoBut ... Rayfish creates a layer 3 network too. It assigns IP addresses to each node. I don't really see why it matters from this point of view whether it uses Iroh or something else to provide its backhaul. That's like saying Wireguard works at layer 4 because it uses UDP. The whole point of VPNs is to offer some kind of tunneling over higher level protocols.
- skulk 3mo agoI always imagined that the application layer had some kind of extra overhead that would be unacceptable for general purpose use.
- aftbit 3mo agoComputers are pretty fast these days. It depends on exactly what kind of general purpose use you're talking about. Trying to push 10 Gbps through a slow old machine? You're doomed. Trying to run SSH, browse the web, or even watch Netflix over a tunnel? Probably fine to send the packet up and down the stack an extra time or two.
- dfish 3mo agorayfish is a layer-69
- dfish 3mo agoI didn't really knew what Nebula was until I saw the comparison made by claude. I tried solutions like tailscale before but never nebula. If you like that product keep using it. The `it's nebula minus X feature` doesn't really fit here
- rsyring 3mo agoInteresting project but can't find anything useful about the author's background on GitHub. Commit history shows the project is a couple weeks old and the commit velocity only seems possible with heavy LLM involvement. Not unexpected but worth noting. The repo's CLAUDE.md is huge which conflicts with published best practices around agent instructions and makes me wonder how much experience the author has using LLMs. All that said, I'd like to use something like this for my personal devices since my personal and work Tailscale networks still can't run at the same time. But there aren't enough trust signals for me for this project yet.
- dfish 3mo agoHello. Yeah this is my secondary account. Main one is dgrr. I still dont do much there. I have projects in github.com/infinitefield and now rayfish. Indeed yes I do not use LLMs too much. Rayfish was a project we had pending for years and I had a lot of sketches about it in my obsidian folders. After the release of iroh v1 I decided to try out claude and prompt it to solve the problem. Still, there is a lot of boilerplate and over time it will become much more like a handmade project assisted by LLMs than anything. That said, it is not my main focus, although I use the product of course. Contributions are always welcome.
- rsyring 3mo agoThanks for taking the time to reply.
- jasonjayr 3mo agotinc (https://tinc-vpn.org/ https://tinc-vpn.org/), a OSS mesh vpn that has existed for a long, long time, is another great solution with no central server. You can manage the public key distribution yourself, or just keep them checked into a git repo (my preferred solution), and it's been solid for years.
- kamranjon 3mo agothank you for the tip here! would you say tinc can work more or less like tailscale? I saw this: "As long as one node in the VPN allows incoming connections on a public IP address (even if it is a dynamic IP address), tinc will be able to do NAT traversal, allowing direct communication between peers." And wondered if tailscale was doing a bit more magic than tinc is here?
- miggol 3mo ago> And wondered if tailscale was doing a bit more magic than tinc is here? Yes, tailscale, rayfish, zerotier and all use an existing network of relays to do nat traversal. Tinc doesn't provide that, but allows you to be completely independent if you get (or already have) a $5 VPS.
- dfish 3mo agoYes. There are good solutions out there. I just build rayfish because I want truly decentralized networks. My thought process is more like: what if you have your job's network and your gaming network? if you use tailscale you need to log off of one, log into the other. Still, you have centralized coordination servers and so on. With rayfish we also discard the ACL architecture and use network separation + per-device firewalls. So it is also trustless. In some way
- keepupnow 3mo agoIt is wrong to describe these P2P products as server-less. In order to connect two peers over WAN it needs a form of coordination server. Since Rayfish appears to be a Claude coded wrapper over Iroh it should at-least give credit to use of Iroh's discovery and relay nodes.
- throwawaypath 3mo ago>Since Rayfish appears to be a Claude coded wrapper over Iroh it should at-least give credit to use of Iroh's discovery and relay nodes. But that would take understanding network fundamentals, architecture, etc. Who needs any of that cruft any longer?
- deleted 3mo ago[deleted]
- keepupnow 3mo agoLol thats right who needs this now we have gpt duh
- dfish 3mo agoWe do have understanding of networks. Claude doesn't come up with concepts by itself. It is not too good to do that yet. We run an HFT firm as a main enterprise, not an easy job. Requires a lot of network fundamentals understanding.
- jarym 3mo agoIroh can use multiple discovery methods, one of them is DNS. When a node comes online it publishes its addresses[1]. Another node can resolve from the node id those addresses and attempt a direct or hole-punched connection. If that works, relays aren't needed. So agree not serverless, but also does not NEED a coordination server (unless you class DNS as a coordination server which is debatable). [1] https://docs.iroh.computer/concepts/address-lookup#endpoint-address-lookup-via-dns https://docs.iroh.computer/concepts/address-lookup#endpoint-...
- dfish 3mo ago
- loxodrome 3mo agoThis is cool, I'd like to try it, but how can I use it to connect peers over the public internet?
- preisschild 3mo agoNowadays I question the necessity of vpn overlay networks. Why not just serve QUIC/HTTP3/Iroh over the internet directly in your application? And use oidc/client cert for authn/authz
- ElectricalUnion 3mo agoI believe the main usecases for this is not requiring changing code, not requiring adding a reverse proxy in front of code I can't change, and "OSI"ish protocols (as in, not really TCP protocols - Remote Database Access, Oracle Net Services/Java Message Queues/X.500, LDAP/smb/ncacn_np). Those days, rather that actual "vpn overlay", I use Tailscale myself mostly for the Tailscale Funnel - a somewhat stable, yet free arbitrary DNS and free reverse proxy termination of incoming data for anonymous users.
- preisschild 3mo ago> Remote Database Access Postgres also has TLS + oauth2 support > rather that actual "vpn overlay", I use Tailscale myself I actually already had tailscale in mind when talking about "vpn overlays" :D
- dfish 3mo agoYes, you can also do it. VPN is just one of those applications to be honest. Think of it as relaying packets over iroh.
- gz5 3mo ago3 vpn segments: 1. foss, p2p-only, no server or intermediate nodes to trust (rayfish) 2. foss, brokered if necessary with all nodes self-hosted (openziti, nebula, some wireguard variants) 3. non-foss, mix of p2p and brokered, host some of the nodes yourself (openvpn, myriad of wireguard variants/wrappers like tailscale, headscale, netbird, netmaker) why is #3 so much more popular?
- apitman 3mo agoSome other similar projects: https://github.com/anderspitman/awesome-tunneling#overlay-networks-and-other-advanced-tools https://github.com/anderspitman/awesome-tunneling#overlay-ne... Interesting to see this built on Iroh.