frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Netrinos – A keep it simple Mesh VPN for small teams

https://netrinos.com
46•pcarroll•2d ago
I'm the founder at Netrinos. I built a WireGuard-based mesh VPN because remote access has always been a pain. After years of SSH tunnels, IPsec headaches, and the ssh log horror movie, I wanted something simpler: install, sign in, get work done.

Netrinos creates a LAN-like overlay network across your devices. Connections are direct P2P via WireGuard, with no central server routing traffic. Each device gets a stable IP and DNS name (pc.you.netrinos.com). When direct connections fail, they fall back to a relay server that's still encrypted end-to-end. We can't see your traffic.

The most challenging problem to solve was NAT traversal. UDP hole punching works most of the time. The rest is a cocktail of symmetric NAT, CGNAT, and serial NATs. We use STUN-style discovery and relay fallback for the edge cases. I was surprised by how unreliable low-end ISP routers really are, and how much technical wizardry it takes to hide that behind a clean, simple UX.

Our stack is a Go backend for client and server, WireGuard kernel mode for Linux and Windows (macOS is userspace), Wails.io for cross-platform UI. WireGuard does all the heavy lifting. Go ties it all together.

Popular use cases include: RDP to home PCs, accessing NAS without exposing it, and SSH into headless Linux boxes. One customer manages hundreds of IoT devices in the field, eliminating the need to deal with customer routers.

We just released Pro with multi-user, access control, and remote gateway routing. Personal is free (up to 100 devices).

I'd love to hear what you expect from a simple mesh VPN, what's missing from current tools, and what's lacking from your remote access setup. Use code HNPRO26 for a 30-day trial of Pro.

https://netrinos.com

Comments

dewey•2h ago
What's the main differentiator between Tailscale and Netrinos?

Edit: Just found this post https://netrinos.com/blog/tailscale-alternatives-2025, so it looks like main differentiator is pricing right now.

felixg3•2h ago
You again under the posts that tickle my fancy…
sh3rl0ck•1h ago
One's banned in my hostel because of a stupid sysadmin.

One isn't.

bongodongobob•1h ago
Not allowing random VPN connections on a LAN is pretty standard. I've been surprised at how many people here are able to use tailscale and the like. Guessing it's just because there are likely smaller teams here that don't have any kind of managed network.
antonvs•20m ago
Smaller teams, yes, but also it seems as though the SaaS explosion has led to many enterprises significantly relaxing the "hardness" of their network boundaries, at least when it comes to integration with companies whose services they depend on. I've seen Tailscale and tools like ngrok being approved to get into large enterprises who you might think wouldn't allow it. Some of these enterprises will set up a bastion in a DMZ to control that, but I've been surprised by how many don't do that.

That relaxation tends to have ripple effects - once you allow tunneling tools in for one purpose - like SaaS integration - then it becomes more normalized and people start using it for other purposes.

observationist•18m ago
Someone is making your IT team do extra work without a good understanding of their systems if they're banning tailscale or granting special network level access thinking that ip or mac address based profiling is secure.

Your network should be zero trust. That means you want to treat every host that connects as if it's on the public internet; the corollary to that is you should give your hosts access to the public internet, unrestricted, and treat your users like adults who don't need micromanaging or constant surveillance (do sane logging, ofc.)

If you need a host that's subject to continuous surveillance, design it as such and require remote access with MFA, and so on.

Give your end users as much freedom as possible, and only constrict it where necessary, or you're going to incentivize shadow IT, unintended consequences, and a whole lot of unnecessary make-work that doesn't contribute to security.

Unrestricted access forces change management, design choices, and policy to confront each user and device for the attack vector they are, and to behave accordingly.

pcarroll•1h ago
Would you mind revealing which one is banned? I wonder what they are using to make that determination.
felixg3•2h ago
I really like your fair differentiation and feature comparison vs Tailscale, netbird etc.

Love to see the ecosystem of wireguard based services growing into different business segments, i.e. you targeting SMBs/small teams.

Not for me, but legitimate use case and product :)

Can_K•2h ago
Full disclaimer: huge Linux fanboy here.

Not really related to the product itself, but your landing page design looks close to the official Microsoft style which I dont have the best memories of..

It might be intentional to show the "seamless integration" to Windows users but my penguin loving soul got scared!

pcarroll•1h ago
Thanks for that feedback. I share your feelings about Linux. It never occurred to us that it would be reminiscent of old MS days. We were going for "clean and uncluttered".

If it makes you feel better, all core development for Netrinos is done on Linux. Then, the code is adapted to work on macOS and Windows. Almost all of the code is cross-platform, including the UI. Only the implementation details are platform specific.

e.g. Linux uses nftables. MacOS uses pfctl. Windows, we had to write our own packet filter to avoid touching the often misconfigured Windows Firewall.

tjfl•2h ago
The GitHub link on your website is 404 (https://github.com/netrinosnetwork)
indianmouse•1h ago
Yep. Stating Github and providing a non existent Github link is a serious redflag which brings trust issues.

Either provide the Github (for whatever reasons) or remove the link from your website. I am assuming it is closed source.

Personally I don't trust new VPN solutions without published source code!

Alternatives: Tailscale with Headscale or better Self-hosted Netbird if one is a itty-bitty IT savvy.

Netbird (self-hosted) offers a lot lot more with the self-hosted solution. - SSO - Independent networks - Superb policies / ACLs - Keybased onboarding - auto-expiration and a lot more like integrations and what not!

Tough to beat the Netbird Open source offering if one tends to spent a little time and effort (though not everyone's cup of coffee!)

Such can look at tailscale's offering since the free version of Tailscale offers more than what is offered here and all the client applications are open source and constantly updated.

If pricing is going to the only difference, (at a high level, everything under the hood looks similar - wireguard based, zero config, p2p mesh, port forwarding etc etc.,) bring a lot more trust by offering an open source version like others.

nickorlow•2h ago
Seems similar in purpose to https://vpncloud.ddswd.de/
nickorlow•2h ago
(above is very easy to use and works very well w/ my experience)

Only downsides are no mobile support & seems to be somewhat abandoned

wolrah•17m ago
The "No IT Department" part of your marketing immediately turns me off because that's actively encouraging "shadow IT".

We all get that sometimes companies have IT policies which are outdated and get in the way, but that's a problem for someone up the chain to solve. A team or department deciding to just start doing their own thing with something like this which isn't managed by or even known about by the official company IT is at best a path to future problems if not an immediate compliance problem.

boplicity•5m ago
Compliance, "up the chain", "department", "the official company IT", etc...

These are all things that the target audience either doesn't have, or doesn't want. If the above words are important to you, then you're probably not in the target market.

ImPleadThe5th•17m ago
Can anyone explain to me (someone not so network security savvy) if there are any privacy or security concerns using a wire guard provider like this?

As I understand it, with traditional VPNs, you basically have to trust third-party audits to verify the VPN isn't logging all traffic and selling it. Does the WireGuard protocol address theses issues? Or is there still the same risk as a more traditional VPN provider?

ImPleadThe5th•15m ago
Naive question here: with WireGuard VPN, does all traffic route through the VPN or only those packets bound for the other devices in the mesh?

Show HN: Netrinos – A keep it simple Mesh VPN for small teams

https://netrinos.com
47•pcarroll•2d ago•18 comments

Show HN: Backlog – a public repository of real work problems

https://www.worldsbacklog.com/
71•anticlickwise•7h ago•17 comments

Show HN: Books mentioned on Hacker News in 2025

https://hackernews-readings-613604506318.us-west1.run.app
536•seinvak•23h ago•189 comments

Show HN: DeepSearch – a high-performance SMB directory scanner in Rust

https://github.com/dohuyhoang93/DeepSearch
2•dohuyhoangvn93•1h ago•0 comments

Show HN: Skyler – AI email organizer, shut down due to OAuth compliance

https://skylerinbox.com/
3•sanjaykumar584•1h ago•0 comments

Show HN: WalletWallet – create Apple passes from anything

https://walletwallet.alen.ro/
418•alentodorov•1d ago•106 comments

Show HN: Rust/WASM lighting data toolkit – parses legacy formats, generates SVGs

https://eulumdat.icu
41•holg•19h ago•0 comments

Show HN: Jmail – Google Suite for Epstein files

https://www.jmail.world
1448•lukeigel•1d ago•335 comments

Show HN: Python Local Sandbox Code Execution (Podman and Uv)

https://github.com/portofcontext/pctx-py-sandbox
2•pmkelly4444•3h ago•0 comments

Show HN: Shittp – Volatile Dotfiles over SSH

https://github.com/FOBshippingpoint/shittp
129•sdovan1•1d ago•78 comments

Show HN: RenderCV – Open-source CV/resume generator, YAML to PDF

https://github.com/rendercv/rendercv
88•sinaatalay•1d ago•40 comments

Show HN: HN Wrapped 2025 - an LLM reviews your year on HN

https://hn-wrapped.kadoa.com?year=2025
296•hubraumhugo•2d ago•150 comments

Show HN: The Official National Train Map Sucked, So I Made My Own

https://www.bdzmap.com/
75•Pavlinbg•1d ago•22 comments

Show HN: Make your own Danish Julehjerter (Braided hearts)

https://juleflet.dk
3•thomasahle•6h ago•0 comments

Show HN: Yapi – FOSS Terminal API Client for Power Users

https://yapi.run/blog/what-is-yapi
4•jamiepond•7h ago•1 comments

Show HN: I built a 1‑dollar feedback tool as a Sunday side project

https://onedollarfeedback.com/
14•jeremy0405•18h ago•1 comments

Show HN: Mushak – Zero config zero downtime Docker/Compose to server deployment

https://mushak.sh
27•hmontazeri•1d ago•15 comments

Show HN: AI-Augmented Memory for Groups

https://www.largemem.com/
10•vishal-ds•6d ago•4 comments

Show HN: Agent/Claude skill for creating ChatGPT Apps

https://github.com/BayramAnnakov/chatgpt-app-skill
2•Bayram•12h ago•1 comments

Show HN: Open-source Markdown publishing framework for AI agents and developers

https://github.com/waynesutton/markdown-site
2•waynesutton•12h ago•0 comments

Show HN: Sentence Starters – Phrases for academic and professional writing

https://sentencestarters.net
4•superhuang•13h ago•3 comments

Show HN: Claude Code Plugin to play music when waiting on user input

https://github.com/Sevii/agent-marketplace/blob/main/plugins/elevator-music/README.md
54•Sevii•2d ago•14 comments

Show HN: Open-source Markdown research tool written in Rust – Ekphos

https://github.com/hanebox/ekphos
34•haneboxx•6d ago•15 comments

Show HN: TinyPDF – 3kb pdf library (70x smaller than jsPDF)

https://github.com/Lulzx/tinypdf
250•lulzx•3d ago•32 comments

Show HN: Mactop v2.0.0

https://github.com/metaspartan/mactop
26•carsenk•15h ago•1 comments

Show HN: Real-time SF 911 dispatch feed (open source)

https://sfpoliceblotter.com
3•1zael•15h ago•0 comments

Show HN: Chart Preview – Preview environments for Helm charts on every PR

20•Olu•1d ago•9 comments

Show HN: I automated forensic accounting for divorce cases (3 min vs. 4 weeks)

4•cd_mkdir•15h ago•0 comments

Show HN: Pac-Man with Guns

https://pac-man-with-guns.netlify.app/
6•admtal•16h ago•0 comments

Show HN: Picknplace.js, an alternative to drag-and-drop

https://jgthms.com/picknplace.js/
450•bbx•6d ago•151 comments