Meshbird – Distributed private networking
github.com
github.com
> Technologies used
> DHTEach node announce some key in DHT network, that represents hash of shared secret key.
"Just took a quick look at the crypto implementation. It uses AES-256 in CBC mode but..... without an authentication tag (HMAC)."
Any response?
This sort of thing is incredibly dangerous. Props to you for coming up with a great UX, but crypto is very, very difficult to get right.
IIRC according to google a few years ago, something like 10-20% of STUN/TURN traffic needs to be routed over the TURN relay server.
This is a gateway.
Edit: found explanation on ZeroTier blog: https://www.zerotier.com/blog/?p=833
For example, you can easily build Cassandra, MongoDB or PostgreSQL cluster on top of Meshbird networking in different countries.
But if you're ok with discovery going through master/server and then connecting directly to peers for traffic, I'd stick with Wireguard.
https://debian-administration.org/article/695/Joining_dispar...
Haven't found anything else quite like it.
Running a VPN between only 4 machines wasn't that useful, and it needs a central server. I quite like Meshbird's idea of using DHT instead. If it ever evolves to improve its crypto and setup, I might take it up instead.
There is a PDF by the original author that explains the difference from "VPNs".
A reachable IP address and a TAP device are the only requirements.
For example, two edges can also be supernodes. A third party supernode would only be needed for the initial connection. Once connected, then each can use the supernode run by the other. The third party is no longer needed. No central server.
As for DHT, who runs the DHT bootstrap server?
Do DHT users run their own bootstrap servers?
Do users exercise any control over the DHT? Who does?
Presence of an Android client is important for me. Auto-reconfiguation in a new network (laptop on a public wi-fi, phone on mobile networks) is nice.
"Peer-to-peer discovery" is not important for me, that is, I'm OK with my nodes discovering the network via a control center. (You can self-host the control center.)
No. Thanks.
You're contradicting yourself. If it's not any less secure, then how does using it mean you're not taking security securely? And you're also treating usability as if it's not important, when in fact usability is very nearly the most important part. If your software isn't usable, then nobody will use it, and if nobody is using it then it doesn't matter how secure it is.
At least, that's how I've read it to be.
The problem is tools -- plural. Users think "I have Linux, where do I get the Linux version?" You have to provide arcane instructions for how to add a package repository on Every. Single. Linux. Distribution.
Or you can script it and users can run a command. Still painful, but less so for the user.
As far as the distributions themselves go: they are harder to get software into than the Apple App Store. The rules are arcane and the docs either barely exist or are on wikis that have not been updated in over a decade. The whole process is unnecessarily arcane beyond belief.