<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: narragansett</title><link>https://news.ycombinator.com/user?id=narragansett</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 02 Aug 2026 01:17:18 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=narragansett" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>thanks for the catch :)</p>
]]></description><pubDate>Sat, 01 Aug 2026 16:43:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=49135967</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49135967</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49135967</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Pls see reply above.</p>
]]></description><pubDate>Sat, 01 Aug 2026 13:09:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49134120</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49134120</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49134120</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>You actually bring up a good point. v6 genuinely helps here. It gives every device a routable address, so no nat, but it doesn't open a hole through the firewall, which still defaults to blocking inbound, and it doesn't address authentication. You'd still need something to introduce the peers and verify identity. What v6 changes is that hole punching gets easier and more connections go direct. v6 does kill CGNAT specifically, which is the worst case for hole punching. I would really like to see CGNAT go away, which would happen in a 100% ipv6 world. Weirdly, v6 still isn't close to 100%... v6 good for BitBang and doesn't replace, which I assume was the point you were making.</p>
]]></description><pubDate>Sat, 01 Aug 2026 12:46:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=49133980</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49133980</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49133980</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Yes, I started using AI for coding (Claude Code) after much consternation -- it's been really good at boosting my productivity. This is a passion project I tackle in my spare time, I like coding, but I don't like <i>much</i> of the coding. Much of it is drudgery-- AI is great for that. But there is no substitute for code review.</p>
]]></description><pubDate>Sat, 01 Aug 2026 12:19:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49133786</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49133786</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49133786</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>This is a really useful feature and on the top of my todo list
<a href="https://github.com/richlegrand/bitbang-cli/issues/9" rel="nofollow">https://github.com/richlegrand/bitbang-cli/issues/9</a></p>
]]></description><pubDate>Sat, 01 Aug 2026 12:05:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49133691</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49133691</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49133691</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Yes, that should work. "serve" prints the URL and the 6-digit pairing code to stdout, so your ssh session sees them, and shutting it down is just killing the process.<p>One suggestion for the untrusted-PC part: bitbang serve -ephemeral. That uses a throwaway identity that dies with the process, so the URL is dead the moment you kill it -- rather than persisting and still working later from whatever browser history it's sitting in. --pin adds a second factor if you want one.<p>The pairing code is possibly handy too. If you'd rather not type a long URL on an unfamiliar machine, go to bitba.ng, enter the 6-digit code, and confirm the number it shows you back on the Pi.</p>
]]></description><pubDate>Sat, 01 Aug 2026 02:03:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49130432</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49130432</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49130432</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Remote access lacks a certain amount of sex appeal -- thanks for reading the through the techno-babble and not giving up :)<p>And yes -- open source and self-hostable is a big part it. The other half is that the connecting side can be a browser, so there's no client to install on whatever you happen to be sitting at. Tailscale is a network you join, this is closer to a link you hand someone.<p>Also taking "read a whole bunch of text first" as a hint. That comparison probably belongs higher up the README.</p>
]]></description><pubDate>Fri, 31 Jul 2026 20:35:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49128243</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49128243</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49128243</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>here's hoping! :)</p>
]]></description><pubDate>Fri, 31 Jul 2026 20:25:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=49128153</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49128153</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49128153</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Iroh's discovery is genuinely neat, and node-IDs-as-public-keys is similar to bitbang.<p>A browser can't join a DHT though because of no UDP sockets, so the connecting side would need a native client, which is the thing bitbang avoids. And DHT lets you locate the peer, but you still need somewhere to trade SDP and ICE candidates, so the rendezvous stays either way I think.<p>What I can do is keep the broker small enough that self-hosting is realistic, which is where it is now -- no accounts, no registry, nothing that grants access, only a simple broker.</p>
]]></description><pubDate>Fri, 31 Jul 2026 19:41:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=49127706</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49127706</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49127706</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Yes -- if direct P2P fails, everything rides the TURN relay that gets inserted automatically -- it's DTLS end-to-end so the relay only sees ciphertext, never plaintext or the access code.<p>On cost: I pay for it on bitba.ng and it's capped right now at 10 minutes per connection (mostly to prevent people from connecting and walking away). But you're not stuck with mine -- the signaling server is open source, so you can self-host and point it at your own TURN. The Python library supports "bring your own TURN" by specifying (--turn-url, --turn-user, --turn-credential); adding the same flags to the CLI is a small gap I need to close. There are TURN providers that have reasonably generous free tiers.</p>
]]></description><pubDate>Fri, 31 Jul 2026 18:56:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49127231</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49127231</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49127231</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Thank you -- and if you're the Sean who wrote Pion, this is built on your work, so that means a lot. :)<p>The friends case is exactly the gap I kept running into. A mesh VPN is fine for my own devices and hopeless the moment someone else needs in, because now they're installing a client and making an account to look at one thing. Here they get a link.<p>Baking it into self-hosting flows is the right instinct and I'd love help figuring out where it fits. There's already an OctoPrint plugin; Jellyfin seems like the obvious next one.</p>
]]></description><pubDate>Fri, 31 Jul 2026 18:46:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49127114</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49127114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49127114</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>Right, bootstrapping needs a rendezvous point -- that's true of any P2P system, including the wg version. The difference is what the rendezvous knows and costs. Here it holds no accounts, no registry, and nothing that grants access, so it's a phonebook rather than a keyring, and it's out of the data path so it's cheap to run and you can self-host it.<p>On generalizing: wg wins for "put these machines on one network." WebRTC wins on reach, because the connecting side can be a browser -- a phone, a borrowed laptop, a machine you don't administer -- with nothing installed. A wg jumpbox still needs a client on both ends and a public IP for the box. Different tradeoff rather than a strictly better one.</p>
]]></description><pubDate>Fri, 31 Jul 2026 18:04:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49126601</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49126601</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49126601</guid></item><item><title><![CDATA[New comment by narragansett in "Show HN: BitBang – Reach machines behind NAT from a browser, no account"]]></title><description><![CDATA[
<p>It's a single Go binary, shaped like ssh. The main difference is the transport -- WebRTC instead of TCP -- so it doesn't need the machine to be reachable in the first place. Run "bitbang serve" and it prints a URL. Open it in a browser and you get a terminal, a file browser, and a proxy to web apps on that machine's network -- or connect from another terminal. There's nothing to install on the connecting side, no account, no port forwarding.<p>The trick to having no accounts: a device's identity is the hash of its public key, so browser and device verify each other directly. The server keeps no registry, authorizes nothing, and isn't in the data path -- it brokers the introduction and steps aside. About 75% of connections go direct P2P. The rest fall back to a TURN relay that only sees ciphertext. The server is open source and self-hostable -- and since it's out of the data path, cheap to run.<p>BitBang started on an ESP32, as the networking for a tiny telepresence robot. Embedded development is difficult and slow, so this CLI is where I've beaten the security model into shape. The embedded version is next. :)</p>
]]></description><pubDate>Fri, 31 Jul 2026 14:42:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49123802</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49123802</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49123802</guid></item><item><title><![CDATA[Show HN: BitBang – Reach machines behind NAT from a browser, no account]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/richlegrand/bitbang-cli">https://github.com/richlegrand/bitbang-cli</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49123789">https://news.ycombinator.com/item?id=49123789</a></p>
<p>Points: 90</p>
<p># Comments: 37</p>
]]></description><pubDate>Fri, 31 Jul 2026 14:41:13 +0000</pubDate><link>https://github.com/richlegrand/bitbang-cli</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=49123789</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49123789</guid></item><item><title><![CDATA[Show HN: BitBang – P2P tunnels to localhost, no account required]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/richlegrand/bitbang">https://github.com/richlegrand/bitbang</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47675661">https://news.ycombinator.com/item?id=47675661</a></p>
<p>Points: 4</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 07 Apr 2026 14:10:19 +0000</pubDate><link>https://github.com/richlegrand/bitbang</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=47675661</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47675661</guid></item><item><title><![CDATA[Show HN: Qast – Cast anything (files, URLs, screen) to any TV from the CLI]]></title><description><![CDATA[
<p>Hi HN,<p>I built qast because I couldn’t find a tool that “just works” for casting content to a TV. Some TVs support YouTube natively, some do screen mirroring, and only a handful actually show up in Chrome's cast menu. Even when you do get a connection, one TV might accept MKV but not WebM, while another just drops the audio entirely.<p>qast sidesteps the compatibility problem. It takes whatever you give it -- a local file, a YouTube URL, your desktop screen, a specific window, or a webpage rendered via headless Chromium -- and transcodes it on the fly to H.264/AAC. Because practically every smart TV in the last decade supports this lowest common denominator, it just works.<p>(Note: You currently need to be running Linux to use it. macOS/Windows support is on the roadmap).<p>Under the hood:<p>Written in Python.<p>Relies on ffmpeg for the heavy lifting (transcoding, window capture).<p>Uses yt-dlp for extracting web video streams.<p>Uses Playwright to render web dashboards in a headless browser before casting.<p>Auto-discovers Chromecast, Roku, and DLNA devices on your local network.<p>Mostly, I want to get some early feedback. If you have experience wrestling with this problem (especially the endless DLNA quirks) or have ideas for other useful features, that would be fantastic as well.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47232340">https://news.ycombinator.com/item?id=47232340</a></p>
<p>Points: 4</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 03 Mar 2026 13:55:13 +0000</pubDate><link>https://github.com/richlegrand/qast</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=47232340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47232340</guid></item><item><title><![CDATA[New comment by narragansett in "Tiny, hackable telepresence robot for under $100"]]></title><description><![CDATA[
<p>It's completely useless, but I still want one.</p>
]]></description><pubDate>Tue, 22 Apr 2025 16:58:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=43764167</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=43764167</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43764167</guid></item><item><title><![CDATA[New comment by narragansett in "Deshittifying the Internet of Things starts with me"]]></title><description><![CDATA[
<p>Agreed. IoT is a shitshow of ways to grab your data and PaaS monthly fees.  Maker-friendly IoT like this is welcome.  Remember Blynk?  It started well enough, but became just another platform to coral its customers to the paywall.</p>
]]></description><pubDate>Sun, 15 Oct 2023 17:39:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=37891719</link><dc:creator>narragansett</dc:creator><comments>https://news.ycombinator.com/item?id=37891719</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37891719</guid></item></channel></rss>