Iroh global content discovery

41 points by sanqui a day ago on lobsters | 9 comments

[OP] sanqui | a day ago

IPFS is moribund - the funding is drying out and it never seemed to be able to overcome the performance problems. Iroh's next-generation implementation of the idea is finally here - at least most of the puzzle pieces it seems (they aren't making a lot of noise about it yet). I'm excited!

synchronousq | 23 hours ago

Speaking of using mainline DHT for UDP holepunching, I've suspected you could use DHT (or even, DNS) to replace tailscale's coordination servers entirely. I've been working on a prototype for some time, and it seems to work decently well.

pyfisch | 17 hours ago

Iroh has implemented holepunching on top of QUIC. Coodination works using either DNS or the DHT. However the company still provides a relay server for the cases where a P2P connection just can't be established.

rklaehn | 10 hours ago

One thing to add: you can buy non rate limited relays from us https://services.iroh.computer/ if you don't want to deal with operating relays, but you can also self-host relays. We have several users that are doing this.

All code including the relay is open source. It is also possible to embed the relay code into a rust server side app.

tonyarkles | 16 hours ago

https://github.com/mmalmi/nostr-vpn is doing something similar using nostr relays for coordination and identification.

chriswarbo | 21 hours ago

Very interesting! I've been wrestling with these same issues, to see if there's a way to get things working without having to invent anything new (which requires convincing other people to adopt it).

I've been using pkdns to resolve pkarr records via DNS, which is more general than a browser plugin.

Using address:port combos as a database key is hacky, but smart; with proof that we can communicate via that host:port combo being used as our write permission.

icefox | 10 hours ago

So we need a tiny extra UDP address index service (udp-addr-index) to provide this mapping.

This feels close enough to STUN or TURN that I wonder if they could be repurposed. Probably not, but...

Conversely, I wonder what a malicious actor could do with spoofed UDP source addresses...

viraptor | 9 hours ago

what a malicious actor could do with spoofed UDP source addresses...

Ideally, nothing. The post mentioned that they take care to pad the request, so it's not a useful dos proxy. And all communication should be signed/verified, so a malicious node should at most waste a bit of your time.