Self-hosted HTTP tunnels with SSH and Nginx
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Self-hosted HTTP tunnels with SSH and Nginx
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
aliasxneo · · focus · HN ↗
[1]: <a href="https://dntls.substack.com/p/the-new-internet" rel="nofollow">https://dntls.substack.com/p/the-new-internet
gonzalohm · · focus · HN ↗
aliasxneo · · focus · HN ↗
subscribed · · focus · HN ↗
guessmyname · · focus · HN ↗
benatkin · · focus · HN ↗
toomim · · focus · HN ↗
- <a href="https://github.com/aflin/iroh-webproxy" rel="nofollow">https://github.com/aflin/iroh-webproxy
- <a href="https://github.com/n0-computer/iroh-proxy-utils" rel="nofollow">https://github.com/n0-computer/iroh-proxy-utils
No port forwarding. No public IP required. No special proxy to set up.
Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.
We just need to define a new https:// url, like ... let's call it "irohttps://" maybe, so then you could contact my laptop with "irohttps://<hash>/path?query".
Muromec · · focus · HN ↗
so... ICE/TURN/STUN ? Sorry I forgot which one of them actually works, but they do work
flippingheck · · focus · HN ↗
What toomim is excited about is this combination of technologies, and that's more than just NAT punching.
_def · · focus · HN ↗
Not perfectly, but good enough for port forwarding web interfaces through cgnat
flippingheck · · focus · HN ↗
snehesht · · focus · HN ↗
gonzalohm · · focus · HN ↗
Downside is that some browsers don't handle the certificates properly (especially on phones)
jagged-chisel · · focus · HN ↗
nvme0n1p1 · · focus · HN ↗
zamadatix · · focus · HN ↗
Transformanshen · · focus · HN ↗
esseph · · focus · HN ↗
DominoTree · · focus · HN ↗
Users and their agents are constantly trying to make all sorts of horrible things forward-facing, and what sucks is that there's not a comprehensive way to block this stuff categorically without severely impacting a ton of legitimate usage.
(And yes, we have _very_ easy ways for users to deploy things onto actual managed hosts and make them forward-facing)
aleks_me2 · · focus · HN ↗
[dead]
[deleted] · · focus · HN ↗
[deleted]
superkuh · · focus · HN ↗
jagged-chisel · · focus · HN ↗
tredre3 · · focus · HN ↗
There is a privacy aspect. For example you seem to have watched Meet Joe Black and Six Days Seven Nights recently. Do you care that we know that? Maybe not, but I can also see the porn you enjoyed.
superkuh · · focus · HN ↗
It is much more private to host on your static webserver and link your friend to http(s)://my.ip.goes.here/orwhatever.jpg than it is to use a third party corporate services that both establish third party doctorine of no assumption of privacy and who have a profit-motive to sell your info. Do it yourself and you have a legal assumption of privacy and no one's continued existence is dependent upon selling information about you.
lin7c · · focus · HN ↗
[dead]
jamiesonbecker · · focus · HN ↗
For example, that very first NGINX section allows an attacker to direct their incoming traffic to any arbitrary listening port on localhost. They can even write a simple curl script that would test all of the different ports. This also bypasses any firewall rules that you might have blocking traffic from the outside world.
be very careful following the instructions in this article.
vbernat · · focus · HN ↗
jamiesonbecker · · focus · HN ↗
vbernat · · focus · HN ↗
sish and ngrok are mentioned in the intro along with the reasons I didn't go this way (specific SSH server to run for the first and not self-hosted for the later).
This domain is crowded with solutions. I only explored that myself because the "free" solutions only requiring an SSH client were unreliable, including the free tier of ngrok (broken SSH tunnel).
antoniomika · · focus · HN ↗
sish is a SSH server written specifically for tunneling. You get all of the benefits of SSH, but also automatic TLS, a web console of requests a tunnel has received, and various other features. You can also tunnel more than just HTTP(S). You can tunnel websockets, TCP connections, and even have internal alias connections for using ProxyJump within the tunnel. All stateless and all protected with SSH auth.
If you’re not interested in self hosting, there’s a hosted version at tuns.sh [1] that has multi region support and a few other cool features (including UDP tunneling) as part of the pico.sh [2] membership ($2/mo). Happy to answer any questions in this space!
[0] <a href="https://github.com/antoniomika/sish" rel="nofollow">https://github.com/antoniomika/sish [1] <a href="https://tuns.sh" rel="nofollow">https://tuns.sh [2] <a href="https://pico.sh" rel="nofollow">https://pico.sh
pbreit · · focus · HN ↗
pbreit · · focus · HN ↗
soltanov · · focus · HN ↗
aiXis · · focus · HN ↗
[dead]