Viewing profile — alexmensch
alexmensch
HN member- Joined
- Fri, Mar 16, 2012, 1:44 AM UTC
- HN karma
- 32
- Public activity
- 18 items
- HN profile
- View on Hacker News ↗
About alexmensch
Recent public activity
- story
-
comment
Comment #26253197
Hi Everyone! We launched Twingate on Show HN 6 months ago. Excited to share more about a concept we’re calling “Identity-First Networking” and a bunch of product enhancements & par…
- story
-
comment
Comment #23340336
The most important factor in this decision is maintaining separation of concerns between user authentication (identity provider) and network authorization (Twingate). Since we rely…
-
comment
Comment #23332018
Gotcha. In your example: nothing. We're okay with that. The level of security that results from the setup you described is what we are hoping Twingate will bring to people with con…
-
comment
Comment #23330965
The client (the Twingate app on the user’s device) actually runs a transparent TCP proxy, so we’re just forwarding TCP payloads to the connector at the other end of the tunnel. Thi…
-
comment
Comment #23330182
These are all valid points, and we’re keenly aware that trust is central to our offering. On the subject of trust, I’d love to get your take on my response to hlieberman’s comment …
-
comment
Comment #23329794
Could you clarify a bit on "out of band" in this use case? In principle, if you have a way to access your bastion on a completely private--maybe physically separate / leased line--…
-
comment
Comment #23329588
Our general approach is to rely on widely-used delegated trust mechanisms (eg. OAuth, SAML, CAs, etc.) and from our perspective the more of that we can do the better, as it helps d…
-
comment
Comment #23328851
This is our very first public launch, and auditing/analytics are next up on our roadmap! Just to be clear, we do not currently and do not plan to intercept any traffic—any client a…
-
comment
Comment #23328605
Hey, great question, and your setup seems very secure, but I’m sure it would be nice to reduce some of the overhead. The right way to support your ephemeral bastion use case with T…
-
comment
Comment #23328481
Currently, yes, we’re focused on connecting users with services, but there’s nothing inherent to the underlying technology that prevents us handling service to service communicatio…
-
comment
Comment #23328052
Totally! We've seen some nightmare configurations around separating dev/staging/prod environments involving scripts to change /etc/hosts back and forth and some funky VPN configura…
-
comment
Comment #23327889
Good question! At the absolute limit, connectors are CPU-bound, but it's unlikely that you would hit a CPU limit before you exhaust all available file descriptors or network bandwi…
-
comment
Comment #23327632
There are similarities in the general approach, but the two biggest differences between us and Teleport are: 1) We support native clients on every major platform (Mac, Windows, iOS…
-
comment
Comment #23327223
Thanks! One of the things that we've really focused on is making Twingate super, super easy to deploy. From all of our customers conversations we've found that despite acknowledgin…
-
comment
Comment #23326764
Hi everyone, I’m one of the cofounders of Twingate. Excited to share with the HN community what we’ve been working on over the last 18 months. Twingate is a modern solution for rem…
- story