Holepunch Unveils P2P Platform "Pear Runtime"
pears.com
pears.com
You create a conversation with one or more people and can then launch apps into that conversation. The people on the other side didn't have to have the apps installed. If they liked an app, they can install it with one click and use it in their own conversations. If they wanted to change the app, they can do that too using the built in editor! All across a real-time encrypted p2p channel.
Despite how easy all these new P2P app frameworks are, none of them are as easy as Firestr was.
Example apps
https://github.com/mempko/firestr/tree/master/example_apps
Example p2p drawing application
https://github.com/mempko/firestr/blob/master/example_apps/d...
I've stopped developing it years ago. Maybe I should pick it up again if P2P is becoming interesting again for folks.
I'm keen to test this with others and dive deeper. The docs were a bit vague on what 'identity' means—is it just a username, or more like a public key? The idea of connecting or 'joining' others in P2P apps seems complex for many. Sharing keys or long strings might be intimidating for widespread use.
Did Firestr gain much traction? Was there an effort to expand it? It seems like an opportune moment for a comeback!
Identity is a public key. You have a contact list that you add keys too. When two people exchange keys and add them to their lists, they automatically connect and can have conversations. Exchanging keys you needed another channel (email, sms, etc) or use the introduction system inside the app where you can introduce one person to another.
In regards to total users? I have no idea. By it's design there isn't a central user list. I have no idea who is talking with who using it.
I believe one limitation was that identities were really tied to a device and I never made a phone version of it. So it being limited to desktop limited it's reach as a communication system.
Maybe it can inspire others. I would love to see P2P as the main way to communicate.
The idea of having no user tracking also aligns brilliantly with the ethos of a truly P2P application.
I'm right there with you, hoping to see more decentralised models of communication in the future!
[1] https://keet.io/
This project seems to be using Hyperswarm which I've looked at for use as a peering medium but it seems like it's not supported in the browser. I'd love to implement it if that story changes since it's so easy to distribute apps on the web.
(You) <-- (lots of stuff) --> my modem <--> my router <--> my phone
So like even if you had my ipv6 address, am I really addressable? Like can you ping my phone? Send me files across the Internet?
Right. IPv4 addresses are expensive, so it's uncommon to have more than one at home.
> What changes with ipv6?
Not a lot. You just have many addresses instead of one. If there were no firewall, someone could ping your router or individual devices, as they have different addresses.
> The ISP still owns the IP addresses and is free to reassign them wherever?
Yes.
> It isn't like a phone number where I own the number and have a right (in the US) to port it?
Correct. You would need direct BGP access to use a portable IPv4/IPv6 address. That generally is not available on residential connections.
Is this the same Tether as in the USDT stablecoin that's been accused of pumping up the volume in Bitcoin markets and possibly being secretly insolvent?
I understand that, as it stands today, Holepunch appears to be operated or contributed to by several staff members from Bitfinex and Tether. However, if Holepunch is open source and Tether were to implode, Holepunch would still exist and could be adopted by anyone, irrespective of Tether/Bitfinex, etc., correct?
it's like seeing something was a java applet or activex component in the 2000s
and we know that because they’ve been investigated by multiple authorities in the US and paid fines for that specific reason?
just making sure we are on the same page about the controversy
Banks are allowed to have fractional reserve. Tether's whole promise was that they would keep 1:1 reserves.
Holepunch provides a collection of “small javascript modules” which can be combined to create unlimited P2P apps, from VPNs to communication tools like Keet.
This is the first I've seen of combining the ideas of a P2P framework and a client-side (which becomes "server-side" because a local P2P Client -- is also and/or can become a remote P2P Server) JavaScript execution engine...
Now that's... different! :-) (For lack of a better word!)
At least in a "that sounds novel!" kind of way...
It'll be interesting to see where all of this goes in the future!
It would be nice to see a technical overview, but this is absent from their docs. Looking at their modules reference docs the runtime seems to comprise:
- A distributed replicated log - Peer discover via a distributed hash table - UDP holepunching to set up direct connections - A TCP like protocol running over the UDP connection - Key-based crypto routing (ala wireguard)
I assume there needs to be some servers available to facilitate the holepunching. Not sure how that works.
Not needed. Other phones can help you determine connectable ports. You can create a phone-to-phone overlay and even puncture carrier-grade NATs. See our birthday paradox attack and initial dozen SIM cards measurements: https://arxiv.org/abs/2311.04658 Older university project, similar to Holepunch with more dev docs: github.com/Tribler/trustchain-superapp/
Having now read the actual article, I'm not sure what I actually read. There was so much ad speak, I think it was "disrupting web 2.0 with serverless P2P aps"?
https://www.researchgate.net/publication/200753717_Challenge...
(from 2009)
P2P stuff is really hard.
Keeping links open P2P requires keepalive because NATs will time out. Even with IPv6 there are usually stateful firewalls in the way that will time out. This means you're constantly sending little packets, and if you have a lot of links there's a lot of keep alive cycles that have to be serviced. This keeps radios and baseband hardware from being able to sleep, draining the battery faster.
Mobile devices almost always have IPv6 on cell networks these days, which makes the actual hole punching almost 100% successful.
Middle boxes in general have to be treated like natural laws or acts of god by developers. There’s like zero chance of affecting them outside the very narrow homelab segment. Even enterprise vendors generally can’t persuade companies to alter policies there.
But you could still use it wherever it's available. Mobile devices spend a significant proportion of the time on home WiFi networks.
And there are only three major US wireless carriers. That isn't a matter of convincing a million absentee corporate firewall administrators, it's a matter of convincing three specific entities, any one of which would be a major win.
I'm half tempted to start making "enterprise firewalls" (i.e. a thin wrapper around Linux netfilter running on commodity hardware) and then enable RFC6887 by default and put a warning in the documentation not to turn it off because forcing applications to tunnel traffic over outgoing HTTPS can impair the functionality of intrusion detection systems and remove valuable information from audit logs.
1. wake up & enable radios
2. see if peers are in range
3. gossip updates for 30 sec
4. sleep for 5 minutes
5. repeat
Aha. Who pays for it?