8 ms·
How to build your own VPN, or: the history of WARP
- fragmede 10mo agoat Cloudflare scale, absolutely. But today? Find a friend that lives in a different legal jusrisdiction that you trust. Install Tailscale on a raspberry pi Zero. Configure it all up. Send it to your friend. Get it on their wifi. Set up the corresponding app on your phone. Connect to it and use it as your exit node. Voila, VPN!
- aborsy 10mo agoThis is something that everyone says and nobody does. Do your friends do that? The majority of people have no idea what is VPN or Tailscale and would be suspicious that you might be placing a hacking device or proxy for visiting bad websites in their home.
- kro 10mo agoSome people also do run Tor exit nodes on their ISP connections, of course receiving tons of abuse complaints, but apparently it's legal enough.
- inemesitaffia 10mo agoSo people may be willing to do it for strangers in exchange for paying the bills.
- yoavm 10mo agoMy siblings and I live in 3 different continents. We use Tailscale exactly for that. It's also installed on some of the VPS I own, so all-in-all we have around 7 exit nodes in different countries to choose from. It was really a breeze to set up. The best part is that our IPs never seemed to be blocked by any service provider.
- spwa4 10mo agoIsn't ssh -D + configuring a socks proxy in your browser a lot easier and faster? (using one of the many proxy switcher extensions) It would only work for the browser (although you do have socksify), but much quicker to set up and only ssh needs to work. No software install whatsoever. I mean, at least for VPSes, of course this won't work without an IP to connect to, or an IP behind NAT. But: no software install.
- fragmede 10mo agoWhere do you SSH to? You need to install sshd on that system somewhere, somehow? Your preferred software seems easier to install, and it is, for you. Others don't have the same experience though. How do you configure apps on your phone to use a socks proxy? We could rathole on what constitutes "a lot" easier, but that doesn't seem interesting so I'll just point out that there's a Tailscale app for Apple TV.
- dns_snek 10mo agoConsider the case where a non-technical person wants to watch US streaming services from their smartphone. No software install, but 5% of the features and 1% of the usability.
- yoavm 10mo agoWith Tailscale, my clients and my exit nodes can easily include Windows machines, Apple laptops, Android phones etc. And I can explain to my siblings how to set it up in 5 minutes, without them ever needing to hear about a terminal.
- fragmede 10mo agoThe thing that Tailscale also allows you to do is access systems on the tailnet, without exposing those servers to the Internet. For the self-hoster with friends, this is really really useful. Do I think this is a thing that more people than you think are doing? Given that you're questioning if it happens at all, I'd say yes. Do I think this is at all common or normal? Absolutely not. My friends and their friends are very technical compared to the general population, so it's not surprising that something "weird" like this would be overrepresented, but even then it's not commonplace to share with friends. You really need some tight-knit bonds in order for it to work. Bonds that many people don't have a ton of. I should mention though, it's not just "bad" websites. A lot of websites geolocate, and for foreign nationals, those websites don't make content available outside the country (for whatever reason). So for a taste of streaming TV from home, a residential proxy in the home country does the trick to let them watch "local" news of home.
- silisili 10mo agoThere's zero chance I'd put some random device from anyone, even a friend, on my network - especially if I knew that was its purpose. Sounds like a huge liability. Do people really do this?
- gear54rus 10mo agoDefinitely. In the age of the internet where stupid 'legal'/commercial/whatever other restrictions are the norm it's the only way to guarantee access.
- hansvm 10mo agoIt depends on the friend, but I definitely wouldn't be opposed to it.
- pirates 10mo agoRandom device? In this scenario you and your friends would have already hashed out what exactly they’re sending you and what it’s for, right?
- invaliduser 10mo agoMost people have no sense of security. They say yes to strangers if asked to plug in a USB device on their laptop. When I said no in the train to someone asking to plug their device "for charging", I was definitely the bad guy. Just find anything plausible, for backup storage, or say, to share family photos with grand parents but it does not work on my home wifi because my ISP is blocking ports, whatever.
- Arainach 10mo agoSo now the plan is to lie to people to get them to do something for you under false pretenses?
- 3oil3 10mo agoAh man, this must be rethorics and you wouldn't lie to a friend close enough to do such a favour, would you? WHo the h is after you guys anyway, to want such level of degraded-internet-speed? And about 'Warp', is it or is it not a VPN after-all? They mentionned they aren't a VPN, but that they build on wireguard ??
- vjerancrnjak 10mo agoWon’t work if behind CGNAT or will be insanely slow. Even ipv6 is not advertised sometimes. I miss the days when I could ssh to my computer with ddns.
- hdgvhicv 10mo agoChoose an isp which gives you a static ipv4 address then.
- deleted 10mo ago[deleted]
- vjerancrnjak 10mo agoHard to find. I ask for advertising an ipv6 address and they don’t want to do that. Even though they give me an ipv6 prefix.
- Jnr 10mo agoTailscale uses STUN to do hole punching, there is a big chance that nodes would be able to achieve direct connection even if both are behind NAT.
- mintflow 10mo agoExit node really is a handy solution for build private vpn for sharing. I have build a vpn called Echo VPN for apple platform which actually use tailscale open source core. Also I think there is another benefit is that wireguard can be DPIed easily now adays, but DERP leverage HTTPS and upgrade which can do some obfuscation too
- deleted 10mo ago[deleted]
- deleted 10mo ago[deleted]
- rasengan 10mo agoThere’s the VPN technologies and then there are VPN services [1]. Technology alone does not give you the service. [1] https://vp.net/l/en-US/blog/The-History-of-VPNs-and-Logging https://vp.net/l/en-US/blog/The-History-of-VPNs-and-Logging