Show HN: BitBang – Reach machines behind NAT from a browser, no account
Posted by narragansett 1 day ago
Comments
Comment by narragansett 1 day ago
The trick to having no accounts: a device's identity is the hash of its public key, so browser and device verify each other directly. The server keeps no registry, authorizes nothing, and isn't in the data path -- it brokers the introduction and steps aside. About 75% of connections go direct P2P. The rest fall back to a TURN relay that only sees ciphertext. The server is open source and self-hostable -- and since it's out of the data path, cheap to run.
BitBang started on an ESP32, as the networking for a tiny telepresence robot. Embedded development is difficult and slow, so this CLI is where I've beaten the security model into shape. The embedded version is next. :)
Comment by cure_42 19 hours ago
Not judging or brigading, just personally don't want to add a new tool to my toolbelt knowing it's made with ai right now. Is bitbang made with ai?
Comment by narragansett 12 hours ago
Comment by dingensundso 15 hours ago
Comment by gtoubassi 1 day ago
Comment by tadasv 1 day ago
I had a similar idea but for wireguard only, where you would allow people to join a vpn through a "shared" jumpbox. To get started with wg is very simple, the problem is the same you need public IP address to scaffold everything.
Out of the two options I probably would prefer going wg route, just because it generalizes better. But this is a pretty cool demo of webrtc.
Comment by nighthawk454 1 day ago
I think Iroh has a way of doing it using either DNS or BitTorrent DHT. Not perfect but fairly decentralized
Comment by narragansett 1 day ago
A browser can't join a DHT though because of no UDP sockets, so the connecting side would need a native client, which is the thing bitbang avoids. And DHT lets you locate the peer, but you still need somewhere to trade SDP and ICE candidates, so the rendezvous stays either way I think.
What I can do is keep the broker small enough that self-hosting is realistic, which is where it is now -- no accounts, no registry, nothing that grants access, only a simple broker.
Comment by nighthawk454 23 hours ago
Looking forward to trying bitbang! Seems super neat
Comment by spl757 1 day ago
Comment by narragansett 1 day ago
On generalizing: wg wins for "put these machines on one network." WebRTC wins on reach, because the connecting side can be a browser -- a phone, a borrowed laptop, a machine you don't administer -- with nothing installed. A wg jumpbox still needs a client on both ends and a public IP for the box. Different tradeoff rather than a strictly better one.
Comment by owaiswiz 1 day ago
And who bears the cost for that (or does it have some FUP) (bandwidth cant be free/unlimited?)
Comment by narragansett 1 day ago
On cost: I pay for it on bitba.ng and it's capped right now at 10 minutes per connection (mostly to prevent people from connecting and walking away). But you're not stuck with mine -- the signaling server is open source, so you can self-host and point it at your own TURN. The Python library supports "bring your own TURN" by specifying (--turn-url, --turn-user, --turn-credential); adding the same flags to the CLI is a small gap I need to close. There are TURN providers that have reasonably generous free tiers.
Comment by ranger_danger 1 day ago
Could you provide a list of ones you know? Last I looked I wasn't able to find anything fast or reliable.
Comment by tyingq 1 day ago
Comment by fatata123 23 hours ago
Comment by Sean-Der 1 day ago
Self-hosting is pretty these days with docker. Exposing it to the internet is the annoying part. I do Jellyfin via netbird, but that means I don't really share it with my friends. I hope something like this getting baked into self-hosting flows is killer.
My other pet peeve is that people use 'Cloud Services' for File transfer. Sometimes when they are in the same LAN!
Nice work again and I hope it catches on/people understand how great this really is :)
Comment by narragansett 1 day ago
The friends case is exactly the gap I kept running into. A mesh VPN is fine for my own devices and hopeless the moment someone else needs in, because now they're installing a client and making an account to look at one thing. Here they get a link.
Baking it into self-hosting flows is the right instinct and I'd love help figuring out where it fits. There's already an OctoPrint plugin; Jellyfin seems like the obvious next one.
Comment by NWoodsman 17 hours ago
Comment by narragansett 12 hours ago
Comment by narragansett 11 hours ago
Comment by ebb_earl_co 9 hours ago
[1] https://github.com/richlegrand/bitbang/blob/main/whitepaper....
Comment by narragansett 7 hours ago
Comment by ValdikSS 1 day ago
No applications except regular ssh client. Needs an SSH connection on the client as well though.
Comment by TheSkyHasEyes 9 hours ago
I see you posted it before. https://news.ycombinator.com/item?id=26500128
If you want this to have more traction engage with those of us who have/had questions. Please consider an example section once connected to ssh-j.com
Thanks.
Comment by ValdikSS 8 hours ago
Comment by apitman 1 day ago
Comment by narragansett 1 day ago
Comment by CrimsonCape 1 day ago
Now on an untrusted PC i can bingbang into my home network, do stuff with a real keyboard, and then run another command to shutdown bitbang.
Does that sound feasible?
Comment by narragansett 22 hours ago
One suggestion for the untrusted-PC part: bitbang serve -ephemeral. That uses a throwaway identity that dies with the process, so the URL is dead the moment you kill it -- rather than persisting and still working later from whatever browser history it's sitting in. --pin adds a second factor if you want one.
The pairing code is possibly handy too. If you'd rather not type a long URL on an unfamiliar machine, go to bitba.ng, enter the 6-digit code, and confirm the number it shows you back on the Pi.
Comment by Arshad-Talpur 13 hours ago
Comment by fmarasho 1 day ago
Comment by narragansett 20 hours ago
Comment by eqvinox 11 hours ago
(Let's skip the discussion, I don't feel like watching groundhog day today.)
Comment by narragansett 11 hours ago
Comment by eqvinox 10 hours ago
Other than that, discussing IPv6 on HN is… draining at best. It's all been argued a million times at this point. People hate it. People love it. People love to hate it. People hate to love it. I'm done :-)
Comment by Bnjoroge 22 hours ago
Comment by narragansett 11 hours ago
Comment by peter_d_sherman 1 day ago
Then I see the following line in the 'How it compares' section:
"Self-hostable server (open source)": ngrok->No, Cloudflare Tunnel->No, Tailscale->No, Bitbang->Yes
...and I'm like, "It's Open Source Tailscale!"
And now I "get it"! (you know, epiphany, profound enlightenment and all that!) :-)
(Well, it's an open source alternative to Tailscale, to be more precise, and an excellent one at that!)
Great work, Rich LeGrand!
(Another step forward for open source!)
Comment by narragansett 1 day ago
And yes -- open source and self-hostable is a big part it. The other half is that the connecting side can be a browser, so there's no client to install on whatever you happen to be sitting at. Tailscale is a network you join, this is closer to a link you hand someone.
Also taking "read a whole bunch of text first" as a hint. That comparison probably belongs higher up the README.