24 points renehsz 1 hour ago 5 comments

aliasxneo 49 minutes ago | parent

This is one of the core things I've been working towards with DNTLS [1]. I love the idea of tunnels, especially for sharing between private parties. The SaaS providers (Tailscale, Cloudflare, etc.) have done a good job making it really easy on their infra, but it really blurs the line of "self-hosted" to me. Ideally we end up with solutions like this that can be run entirely without an intermediary.

[1]: https://dntls.substack.com/p/the-new-internet

guessmyname 44 minutes ago | parent

If self-hosted, then why do you need a third-party service *.ssh.luffy.cx ?

benatkin 41 minutes ago | parent

You replace it with your domain.

toomim 19 minutes ago | parent

For this stuff, I'm most excited about https over iroh.

- https://github.com/aflin/iroh-webproxy

- https://github.com/n0-computer/iroh-proxy-utils

No port forwarding. No public IP required. No special proxy to set up.

Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.

We just need to define a new https:// url, like ... let's call it "irohttps://" maybe, so then you could contact my laptop with "irohttps://<hash>/path?query".

snehesht 4 minutes ago | parent

I'm working on something similar with userspace wireguard, will share it soon.