‹ BackHN Continuity

Thread

Self-hosted HTTP tunnels with SSH and Nginx

140 points · 32 comments · renehsz

  1. toomim · · focus · HN ↗
    For this stuff, I'm most excited about https over iroh.

    - <a href="https:&#x2F;&#x2F;github.com&#x2F;aflin&#x2F;iroh-webproxy" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;aflin&#x2F;iroh-webproxy

    - <a href="https:&#x2F;&#x2F;github.com&#x2F;n0-computer&#x2F;iroh-proxy-utils" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;n0-computer&#x2F;iroh-proxy-utils

    No port forwarding. No public IP required. No special proxy to set up.

    Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.

    We just need to define a new https:&#x2F;&#x2F; url, like ... let&#x27;s call it &quot;irohttps:&#x2F;&#x2F;&quot; maybe, so then you could contact my laptop with &quot;irohttps:&#x2F;&#x2F;&lt;hash&gt;&#x2F;path?query&quot;.

    1. Muromec · · focus · HN ↗
      &gt;and then port-knock and form a direct connection to each other, perfectly encrypted.

      so... ICE&#x2F;TURN&#x2F;STUN ? Sorry I forgot which one of them actually works, but they do work

      1. flippingheck · · focus · HN ↗
        Yes, and TLS&#x2F;QUIC&#x2F;Wireguard all offer encryption.

        What toomim is excited about is this combination of technologies, and that&#x27;s more than just NAT punching or encryption.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.