Comment by focusgroup0

2 months ago

>We use STUN-style discovery and relay fallback

How does your relay compare to Tailscale's (DERP)?

We implement STUN and TURN functionality natively in WireGuard rather than using separate protocols.

Netrinos uses a central rendezvous server that participates in WireGuard handshakes solely to collect your devices' public endpoints and share that information with your other devices. When a device roams to a new location, the server learns the new endpoint and updates the other devices in your account.

When direct P2P fails, Netrinos connections fall back to a relay server. The relay is a WireGuard peer, but it can only relay traffic between peers in your account. All customer accounts are strictly firewalled from each other.

If you want more control, you can enable a device in your account as a relay server with a checkbox in the app. This could be a home PC with a stable connection or a low-cost cloud server.