Networking
October 2026
← Topics

The Address Is a Nostr Key

FIPS is jmcorgan's Free Internetworking Peering System: a mesh network whose addresses are Nostr keys. Intelligence Snacks 72, with Pete Winn and Andy David, is a plain-language tour. June's nostr-vpn runs on this mesh.

WHO YOU REACH
A machine generates a secp256k1 key, the same kind of key Nostr uses. Other nodes reach it by that public key. There is no domain to register and no central address list. The repository maps the key to an IPv6 address in fd00::/8 and answers names that end in .fips.
WHAT IS ENCRYPTED
Mesh traffic is encrypted twice: Noise IK between neighbouring nodes, and Noise XK between the two ends, with rekey. Those packets are not Nostr events. An ordinary IPv6 program can use the .fips name. A program written for FIPS can skip IPv6 and address npub:port directly.
HOW PACKETS FIND YOU
Nodes build a spanning tree and route greedily toward the destination's coordinates in it. To learn where an npub sits, a node follows bloom filters its neighbours advertise, instead of flooding the mesh.
NOT STABLE
The README says the protocol and APIs are not stable. Current release is v0.5.2, dated 28 Sep 2026. Master is marked v0.6.0-dev. A security audit of the cryptographic protocols is listed as a near-term item, not as work that is finished.

Nostr Is the Rendezvous

The packets do not have to cross a relay. Nostr is one way two nodes find each other when they are not already on the same link.

OPTIONAL
The README marks Nostr discovery as optional. On a LAN, mDNS finds peers with no relay. The same mesh also runs over Ethernet, Wi-Fi, Bluetooth, Tor, and the Nym mixnet. A node can use more than one of those at once.
THE PUNCH
When Nostr is used, a node publishes where it can be reached. The two sides exchange candidates and open a direct UDP path through NAT, with STUN. After that path exists, the traffic is between the nodes. The relay's job was the introduction.
A KEY ON THE RELAY
Through v0.5.1, a node that finished this traversal published NIP-09 deletions signed with its routing key. That placed the node's identity next to the ids of its gift-wrapped offer and answer, on every relay it reached. v0.5.2 stops sending those deletions. A relay keeps the wraps until their NIP-40 expiry.
WHAT THE RELAY SAW
Stopping the deletion does not undo the introduction. A relay that carried the offer and answer still saw the discovery messages. Direct packets afterwards are a separate path from that record.

Release v0.5.2

The release is 28 Sep 2026, after the episode. The notes say there is no wire-format change, so a mixed mesh still works and nodes can be upgraded one at a time.

EVERY NODE
The notes say every node should upgrade. Nostr relay connections move to rustls 0.23.45, past a flaw that accepted TLS 1.3 handshake messages across encryption-level boundaries (RUSTSEC-2026-0285; the handshake stays authenticated). A lost rekey reply no longer splits the link, and a lost session handshake no longer leaves the session one-sided.
THEIR COUNT
The README says the protocol runs end to end on a public test mesh of thousands of nodes, over the transports above. That count is the project's figure.
WHAT THEY DEMO
The episode walks through reaching a machine or a local app at an npub-shaped .fips address, without operating a DNS name. A chapter covers Pete's draft NIP-F5, a window.fipsTransport capability that lets a browser reach .fips services. It is open as nostr-protocol/nips#2469.
QUESTION
If the introduction happens on a public relay, what is still private about who wanted to reach whom, once the packets themselves have gone direct?