Anyone knows a way using these overlay networks, tor, i2p, freenet, to expose a service on a machine behind a NAT to be accessed through the internet without the need of clients needing special software?
Anyone knows a way using these overlay networks, tor, i2p, freenet, to expose a service on a machine behind a NAT to be accessed through the internet without the need of clients needing special software?
(Well you can, but you shouldn't want to, will explain below.)
Freenet is a datastore: It addresses content, not computers.
So a Freenet address points to a file or a directory of files (a zip). The addresses can be versioned so files/dirs can be updated.
A file/dir may be stored anywhere in Freenet. Where it is stored is not known - the machines which store it are anonymous so censorship is prevented. If many people request a file, it will get stored on more machines automatically.
Now of course you can make a specific computer constantly publish new versions of a file to "send" data like on IP and poll for a remote file to receive data. This can emulate direct connections and does work.
But it invalidates the whole point of Freenet:
Freenet wants to be censorship-resistant, so content should not rely on a single computer to keep existing because that is a single point of failure.
- use a VPN from a net-neutral ISP to obtain a real public IP address over VPN (5-10€/mo)
- route specific ports to your own machine from an internet-facing server (via SSH/Wireguard/VPN tunnels) ; unfortunately it makes it impossible for different people (backend servers) to share a single routable port
- reverse proxy specific protocols to a backend server, using for example TLS SNI (or eSNI) headers ; a single internet-facing server can serve many different vhosts to separate backends, where TLS encryption is terminated on the backend
But of course you can run tor/i2p and other crypto-secure routing protocols (yggdrasil, zeronet, cjdns...) to expand the ways to reach your server. I'm unaware of good protocol-agnostic address discovery... for tor we usually do TOFU over DNS (eg. onionMX records) or HTTPS (HTTP2 Alt-SVC headers). The GNU Name System, at least on paper, sounds like the perfect crypto-secure naming scheme that could securely bootstrap addresses from names, but i don't think it has broad adoption yet.