2024-11-18 14:15:11
**What if there is no line, no boundary between tor and clearnet (the 'normal' web)? What if a Damus user on iPhone can talk to their friend's private TOR relay? Let's find out together what can happen by using this new tool which I call Nostr Epoxy! And it's scalable, too!**
**TL;DR Demo video:**
nostr:naddr1qqr5gc20v43hy5czyzamthdqu92k09ulq4p5q77uyqeadu9mkv8hy5f2nqw0mvhsncn5wqcyqqqgtwc5nzpll
| ![](https://blob.satellite.earth/7354f8de9f75d409e86153c6497bfea29cc022f64cab2b38d938731a1b2573c2) | ![](https://cdn.satellite.earth/5615f18247a189897037b29c275212392a28acb9b2fbcc15cae59be6030248af.png) |
| -------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| Phone can reach clearweb relay, but cannot connect to TOR relay | Phone can reach TOR relay |
Proxies have been around forever and can be a powerful tool in getting around network restrictions. In the context of nostr, currently everyone connects to a relay directly, which you may not always want. The relay can keep track of your IP address and build a profile, or your device might be behind a very restrictive firewall which prevents you from reaching a relay.
From this problem, the idea for proxy relays was born. We wanted to reach a TOR relay, without having to install any TOR stuff on our devices. Which on iPhones is especially challenging. So the idea is that we want to extend a relay's functionality so that it can instead of processing requests for itself, it can pass on the requests to another relay that they themselves can reach.
The easiest solution to get this working is in the form of a Reverse Proxy, which you can put in front of any relay, which by default tunnels the traffic to the operator's own relay, for example a Strfry instance. That way the relay implementation doesn't have to change and the user doesn't have to be aware that this relay endpoint can also proxy to other relays. The example implementation is called [NERP - Nostr Epoxy Reverse Proxy](nostr:naddr1qvzqqqrhnypzpwa4mkswz4t8j70s2s6q00wzqv7k7zamxrmj2y4fs88aktcfuf68qy88wumn8ghj7mn0wvhxcmmv9uqpjmn0wd68ytt9wphhs7fdwfjhvetjwdjj6urjdau8j6sn6y7).
| ![](https://cdn.satellite.earth/d124f0ba7bfe0467ce90f2bbf465eef1d67ac0e1dec6732e24432552da7e9c18.png) | ![](https://cdn.satellite.earth/7f9b64ce58f372415e7dfe57b3457069a7ca9a8ce1b69677b1884ebc0e2ebca4.png) |
| ----------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| Reverse proxy default behaviour | Reverse proxy after proxy request |
As shown above the default is to connect to the operator's own relay. So how do we create the proxied connection? Well we send the following request over our websocket:
```json
["PROXY", "wss://relay.com"]
```
Which asks the proxy to change the target from it's own back-end to whatever we specify. In this case `wss://relay.com`. However, it turns out this relay doesn't live in a fiat world, it responds with:
`["PROXY", "PAYMENT_REQURIED", <payment_request>]` where `<payment_request>` is an object:
```json
{
"price": "1",
"unit": "sat",
"mint": "https://some.mint.cash/",
}
```
Which brings us to...
## 💰 Monetizing proxies
Inevitably we're going to hit the "Who's gonna run the proxies!?" question. Well you are, because you want to stack some sats. Therefore we added monetization to these proxies, which is what sets this project apart from current-day proxies on the internet. When the client is hit with the `PAYMENT_REQUIRED` message above, it can retry the first message, but with an additional field, a cashu payment.
```json
["PROXY", "wss://relay.com", "cashuAeyJ0..."]
```
We're now paying a couple sats, (the price above is in sats per minute). If the proxy is happy with our payment, it will start a timer and set up the connection to the target relay. Indicated by a `["PROXY", "CONNECTED"]` message, after which we can go about our relay business until the bought time runs out. After which the proxy will close our connection with code `1000`, reason: `PROXY: Connection Bankrupted`.
The nice thing here is that introducing payments can reduce spam significantly.
### Why Cashu?
Because [Cashu eCash](https://cashu.me) allows us to finally make micro-payments viable and scalable, it can help us to bring an honest monetary reward to the people that do the hard work of maintaining the free and open internet. If you provide a proxy, you get paid and therefore you're incentivised to keep the infrastructure up and running.
Cashu tokens are a very efficient way of sending payments directly. Unlike Lightning, it does not require a back and forth between the two transacting parties. Because cashu tokens can be sent as a string of text, you can attach it to any request/data you're sending around. Even at rest, the money will still be 'physically' there. That means there's no back and forth required to send a payment, like we do on lightning, and people don't need perfect connectivity.
## 💭 Some philosophy
Until now, all web applications have been strongly coupled to the transportation methods they use, mainly http(s). Nostr changes this, because the data that feeds an application can now arrive over any transportation mechanism. WebSockets, Thumb-drives, QR, LoRa (radio) and Heck! even FM and pigeons will work!
Although the above point is not necessarily tied to the use of websocket proxies, it does underline the point I want to make: Because Nostr completely decouples applications from the transportation layer, We can get VERY creative in the ways in which we transport application data... Therefore, the boundaries of the current clearnet network become irrelevant.
Using the websocket proxies, we can now hop from clearnet to tor, to [i2p](https://geti2p.net/en/), to [hyper](https://github.com/hypercore-protocol) and back to clearnet. This significantly reduces the burden on the client by not having to 'know' how any of these other networks work, they won't have to install anything, yet they can interact with relays on these lesser known networks.
## ⚙ Under the hood
Here's a UMl example of a proxy (that does not have a default relay behind it) and the lifecycle of a proxied connection.
![uml](https://www.plantuml.com/plantuml/png/dLBBJiCm4BpxA_O3Gjfp3gXHwWD8926KHq_8n2irIXmNFw3vUn85OaJtGeyxE-ETiMPZdJ3Eguw9sca3cRTEApHicfiFuN210b8QVHfIzhE0g-jl218eZjZ3CxvPNRVes8nFZ8MTW6vfRLaLB_i8FgrDLYk3dHXYAPItSQFfXyfqVyVptMl5xnzlAhwDe1I3mjv1XUyUhVltdGXgOGy-nU5s7STno5nDjE1Ydi_ppl3lOxeDge0-e0FNA3H4iE0mA_ASPpk-POnECWQ7jkabh0bhOKdOua_Znn77bzL56Y9fwKrz41O1JyV6eAJrMQSjKhsPqn0CYN_xAF6yinlivTZkBm00)
## NIP-XX draft
I wrote a draft NIP on how to support proxying [here](https://github.com/ArjenStens/nostr-epoxy-reverse-proxy/blob/main/NIP-XX.md).
## 🛝 Play with it!
I created a [Dashboard](https://swissdash.site) to discover proxies and play with connecting to relays (multiple hops are possible).
![](https://cdn.satellite.earth/9fb3810bd6a7ac147e9a07185e7b4c42c9109f1791296d9ebbf3e7b1530ee7d0.png)
Check out the route-builder tab, add a couple sats to the wallet and route some request through the proxies.
![](https://cdn.satellite.earth/93ce43af5d92ff4f253acb064f0995a21e20dafd29a1dfb7f1ecaef4babcbe5b.png)
![](https://cdn.satellite.earth/1a6163c1486098a45d577639b324c13e9e22bde32ddfae44ffb702702797c59d.png)
## Resources
- [Dashboard](https://swissdash.site)
- **Nostr Epoxy Reverse Proxy** [Source Code](nostr:naddr1qvzqqqrhnypzpwa4mkswz4t8j70s2s6q00wzqv7k7zamxrmj2y4fs88aktcfuf68qy88wumn8ghj7mn0wvhxcmmv9uqpjmn0wd68ytt9wphhs7fdwfjhvetjwdjj6urjdau8j6sn6y7)
- **NIP** [draft](https://github.com/ArjenStens/nostr-epoxy-reverse-proxy/blob/main/NIP-XX.md)