Syncthing Anywhere with Tailscale
init8.lol
init8.lol
Syncthing has a new untrusted feature, which sends encrypted blobs to the nodes you set as being "untrusted" (i.e. nodes in the cloud)
Here's the specs on how it works: https://docs.syncthing.net/specs/untrusted.html
I'm also not a huge fan of the "put thing A on top of general purpose thing that can host all things of the same class as A" trope. Tailscale gives you a virtual network so you can run absolutely anything that speaks IP over it. It's like "how to run (insert random Linux service) in Docker" and similar blogspam.
One could even have the reverse proxy on port 80 forward requests to Syncthing on the inside.
> Tailscale here is optional as Syncthing does the NAT traversal for you and also uses a secure protocol. Syncthing will do its best to establish a peer to peer connection and that’s great!
> However, with Tailscale I can access my “shared directory” via SAMBA on my other devices, anywhere. And also don’t need any “Relay Server” only if my device can’t talk peer-to-peer as Tailscale will do it for me :))
this is so hard to parse, could you rephrase for clarity?
Also did they support mobile recently? I thought they still don't have Android/iOS support ?
Their community seems to be very small; so could you give a short review of what's better/worse about it vs. Tailscale?
A syncthing server is used for discovery only, which is a free service.
I use my NAS for this, that way I don't need to keep my desktop turned on for my laptop to sync to it.
That is, you can’t just point syncthing to any old sftp endpoint…
I think your parent means “the commercial endpoint” when he says “server” …
Every peer needs to have syncthing installed, yes. This is how syncthing works. It's P2P (though there is the public relay servers for NATed peers).
Even if you ran your own relay network, every peer would need Syncthing installed.
What some users might want is an always-on node, so that device A could push to that always-on node and then device B could later download it without requiring device A and device B to be online at the same time, but what that node is, is really just a device C that's always on.
I think you're picturing Syncthing as being like a centralised file host that offers a client to sync to/from it, or maybe like something like Borg or restic. It's not that, there's no master node or central repo or anything.
I use this feature with a friend of mine. We both have NAS', and we both have each other's NAS as an untrusted SyncThing device. (It's also pretty trivial to run a Linode/DigitalOcean low end VPS as an untrusted client. In fact if neither has a one-click install I'd be surprised.)
Also makes me wonder how much Syncthing could be simplified if it could assume all devices have a fixed IP address and direct connectivity.
P2P programs where connections between devices with no common ownership/coordination don't matter (i.e. Syncthing if you're not sharing with other people) could ditch that layer and rely on an external SDN now that they've become easier to use. Of course, that makes those programs potentially less flexible and it requires users to set up another thing™ so I understand why developers of P2P programs might not wanna do that. But in theory it would be nice because we could have all SDN concerns in one system and not duplicated in every program that needs global discovery/connections.
This isn’t (always) true. Some solutions are E2E encrypted.
Among "stand"'s many meanings, it can be a transitive verb meaning to put something in a standing or upright position. For example, my electric toothbrush has a flat bottom, so I can lay it down on its side or stand it up on its end. So, basically "stand up" is a lot like "erect" as in "erect a fence along the property line".
Not a problem for me, the only Apple devices I have are not iOS but I'd imagine a dealbreaker for some.
Which ones do you mean?
With Tailscale, the data channel runs over WireGuard, so it's encrypted between clients but the keys are exchanged over the control plane without end-to-end authentication, as far as I know.
ZeroTier I don't know much about. Does it have some kind of end-to-end key?
Nebula (from Slack) uses certificates, so it does make devices on the live network effectively trustless.