Freelan - an open-source, multi-platform, peer-to-peer VPN software
freelan.org
freelan.org
In the wake of the recent NSA-related news I thought that this stuff may find a new use. If you have an idea and would like to devote some time and effort - you're welcome (I guess my contact info is visible in the profile).
I have no issues opensourcing it, it contains no close licensed and/or GPL-poisoned code. Everything we borrowed was BSD-type licensed. I just want to have some product to opensource instead of just dumping it on the Github and then waiting 4 billion years for life to conceive itself there :-)
Sorry for shameless plug.
Update for "Github ++" commenters: I'm all in to put it on Github (BitBucket is more natural in my case, because it's a Hg repo). But: the architecture was quite well thought out and internal APIs are quite clear, but they're not documented. We didn't have immediate open source plans. You wont be able to figure out how to use it, especially if you're going to use our "lower" layer - NAT traversal and friends. You need to know how it works to build a more universal API on top of it. Trust me, I know what I'm talking about - I did a few experiments with this code about a year ago and I spent a _lot_ of time figuring out how we did this and that. And it was _our_ code, we wrote it and discussed it daily for two years.
[1] https://github.com/quartzjer/TeleHash/blob/master/org/v2.md
The project sound interesting, the comment is very much relevant in today's post-NSA world. So should I downvote, upvote, or not vote at all? If the comment had used a neutral word, rather than a derogatory term, it would not be a question about it.
You can vote whatever you feel like, but I'm not selling my opinion for a vote on HN. My opinion is what it is and I can change it if you either provide sufficient argument or threaten my life, health, family or some other factor of my life, more important than my opinion on OSS licensing :-)
I can provide argument why I think GPL is what I think it is, but I seriously doubt this thread is the right place for it.
You could always include the advertising clause.
We didn't use the clause though and didn't use (as far as I remember) any code which did.
So if you like to be in full control over your advertisement, and your documentation, bsd do indeed "poison" the project. It clearly adds restrictions. I would however not use such derogatory term when describing the BSD. Is it really that hard to avoid using derogatory terms and simply use language without it?
I do not consider "poisonous license" a derogatory term. English is not my native language, may be this is why.
Just as a side note, I found an half year old HN article which talked about the BSD requirements, with suggest that one might want to use ISC license in some cases: https://news.ycombinator.com/item?id=5798431
Not that your project is code for embedded software (or is it? C code tend to be quite fast and have small memory footprint), but it might be an interesting read.
The real trouble with the advertising clause is that it breaks compatibility with several other common licenses. Some of the BSD advocates actually like this because it causes trouble for people who use GPL code (the usual holy war justifications), but the net result is still that you have two otherwise-useful pieces of code that become mutually incompatible for political reasons.
Since then, when I hear "greater good" I feel an urge to kill (only half joking here). And "requiring the source code" sounds pretty much like "greater good" for me. If I'm releasing the code, then I'm releasing it. If I think that some asshole, who invented the best smartphone on the planet, will use it for his own profit and if I feel pain thinking so, I'm not going to release it. Releasing source code and attaching a piece of political agenda to is is not a coding activity, it's a specific kind of political activity - a political propaganda. "When I hear the word propaganda I'm reaching for the gun".
or at least do it and get enough folks excited that some volunteers help add docs :)
do it!
I have been using tinc for quite a long time and it feels pretty stable, but the configuration of new nodes is quite a PITA. For that reason a lot of bootstrapping scripts have been built around this [2]. Also, i love the possibility to easily dump the whole (known) network graph and create great graphs from this info [3].
I am using it mostly for reaching hosts behind NAT and creating a secure environment for these hosts.I never have tried the 'connect whole network' feature.
[1] http://www.tinc-vpn.org/security/
[2] https://github.com/krebscode/painload/blob/master/retiolum/s...
It seems that with 1.1pre3 or 4 they have gotten a new, experimental protocol. Hopefully it is an improvement.
OpenSSH
Can create a full spectrum VPN & supports a stronger and a broader range of ciphers than virtually all competing software, is entirely open source, runs on every platform I can think of, the list goes on. Heck via pointopoint it can even mimic freelan and be peer to peer :)
• TCP-in-TCP (or ${ANY_RELIABLE_STREAM}-in-${ANY_RELIABLE_STREAM}) performs very poorly in the face of packet loss.
• SSH itself becomes a bottleneck on networks with a large bandwidth-delay product because of statically sized buffers in the client and server. (Though there's been some work done in OpenSSH to mitigate that.)
• "Real" VPN software generally has niceties like MSS mangling TCP connections inside the tunnel to help prevent fragmentation of the encapsulated packets due to VPN overhead.
SSH is great when you need a quick and dirty tunnel (I use it in SOCKS mode a fair bit), but it's not something I'd want to use for long-lived tunnels that will see a lot of data.
There are hacks to tunnel SSH over HTTPS ( really ) but at that point you've abandoned the simplicity of SSH and might as well go with OpenVPN.
Also it appears to require root access on the remote machine which would make it difficult to securely let a few people use it. Definitely a useful script for a quick linux to linux tunnel.
http://support.vpnsecure.me/articles/ssh-tunnelling-proxy-tr...
OpenVPN establishes a site-to-site or point-to-site VPN, but routing to the client still goes through the gateway server.
Freelan still requires a known "supernode" to broker the initial connection, but after that, they can either communicate directly or through peers.
--
I just happen to be here doing my first OpenVPN implementation this last few days.
It appears that FreeLAN is all about transparent bridging VPN, rather than routing VPN. Thus, the "LAN" part of the FreeLAN product name is particular apt.
It is noteworthy that the words "Ethernet" and "bridging" are absent from the product FAQ. This is most unfortunate.
NAT traversal is an implementation thing, and I favor Jabber as the out-of-band these days since everyone can get at least a GTalk account.
Though we now have libjingle, which basically merges both of these things and would probably elegantly solve the problem. But p2p vpn's aren't much use if you have to control the NAT router you're attached to.
Isn't that deprecated in favour of Google Hangouts?
p2pvpn <http://www.p2pvpn.org/> uses BitTorrent trackers for it - which is actually a pretty good solution, but sadly also - no NAT holepunching or even UPnP yet.
Though I have been trying to find a VPN which uses a Tor hidden service to define network rendeavous point - since Tor is distributed and available, you could issue invites with the hidden service ID, and then send real IPs to members to establish P2P (so, not using the anonymity, just using it to bootstrap the network). SocialVPN does something similar, but I couldn't get it work reliably in tests (it would go up...then my hosts went down and I couldn't get them to appear to each other again).
Any idea how to run on Windows 2003 32bit server.