· via Hacker News – Front Page (native)
yggstore pools friends' disk space into encrypted sharded storage over Yggdrasil
An experimental tool called yggstore encrypts files, erasure-codes them into shards and spreads them across friends' machines on the Yggdrasil mesh — no coordinator, no cloud, and no independent crypto review yet.
An experimental tool called yggstore, published on GitHub by user peterretief and featured on the Hacker News front page, lets a group of friends pool spare disk space. Every file is encrypted, erasure-coded and spread across the group's machines over the Yggdrasil overlay network, with no coordinator in the middle.
How storage works
According to the project's README, the put command splits a file into 4 MiB chunks and encrypts each chunk with AES-256-GCM, using a fresh random key per file and a new nonce for every chunk. Each encrypted chunk is then erasure-coded into four data shards plus two parity shards. Shards are content-addressed — a shard's filename is its SHA-256 hash — and distributed over the peers that are online, at most one shard from any given chunk per peer when six or more are reachable.
Because any four of a chunk's six shards are enough to rebuild it, a file survives individual shards going missing. The README says no node ever holds more than two shards of one chunk, so one machine failing never takes data with it; nodes that share a physical box, such as Docker containers, can carry a shared host tag so the cap applies per machine — at the cost of needing three real machines online for uploads.
The uploader keeps a small .ystub file containing the manifest, including the file's key, so anyone holding the stub and access to the group's nodes can read the file back. Retrieval fetches shards in parallel, discards any whose hash doesn't match, and rebuilds each chunk from any four of its six shards. A peer flagged as slow receives just one shard per chunk so it doesn't hold up uploads.
Proving peers still hold your data
With no coordinator policing the swarm, yggstore adds a proof-of-possession scheme. At upload time, while the shards are still in hand, the uploader precomputes twenty single-use challenges per shard — essentially requests to hash a chosen byte range under a supplied nonce — into a separate challenges file that must stay private. The verify command later sends one challenge per shard and checks the answers, confirming that peers actually hold what they were entrusted with.
Identity and access control
Identity leans on Yggdrasil's own addressing: a node's 200::/7 address is derived from its public key, so the source address of an overlay connection identifies the caller cryptographically. Servers are deny-by-default, answering only addresses listed in a local peers., bind only to their overlay address, and allow only the original writer to delete a shard. A built-in Yggdrasil mode runs the overlay inside the tool itself, with no separate daemon, TUN device or root privileges.
New members join through one-time invites valid for seven days. The join endpoint is the only call a non-member can make, does nothing without a valid invite, and is rate-limited to six attempts per minute. An admin node keeps every node's peer list in step, propagating changes to all nodes within a minute and without restarts.
Sending a file by sending a stub
Sharing deliberately avoids the storage network itself: to give someone a file, you seal the item's name, a note and its key into a .ysend file that only their sharing code can open, then deliver it by email or any other channel. Dropping it into their yggstore install restores the file, since nodes hand out shards to members alone. The README warns that a received item still belongs to the sender — if they delete it, it disappears for everyone they shared it with — and that received stubs can only reference Yggdrasil addresses or locally known nodes, so a crafted file cannot redirect a restore at arbitrary machines.
More than storage
The README sketches a wider platform on top of the core: a gateway that lets paying customers use a group's pooled storage from S3-compatible clients such as rclone, Cyberduck and Duplicati, with members choosing whether their box holds customer data and earning credit for it; per-file version history that stores only the parts that changed; direct messages and publish/subscribe topics delivered even to nodes that were offline at the time; folder publishing so several machines serve one website; and inbound email to your own domain, each message encrypted as it arrives. There is even a step-by-step guide for building a storage box from a second-hand mini PC, and binaries cover Linux PCs, Raspberry Pi and other arm64 boards, Windows and macOS, or you can build it with Go 1.24 or later.
Why it matters
yggstore is a fairly complete sketch of coordinator-free group storage: key-derived identity, deny-by-default access control, erasure-coded redundancy, proof-of-possession challenges and sealed-stub sharing, all without a server anyone has to run for strangers. The lend-a-disk model among friends, with an S3 gateway bolted on, is an unusual middle path between cloud storage and fully open peer-to-peer systems. The project is blunt about its maturity, though: the cryptography has not been reviewed by anyone independent, and the README's own advice is to never make anything stored with it the only copy of data you can't afford to lose.
- #p2p
- #storage
- #encryption
- #yggdrasil
- #open-source