Live data from Hacker News

Viewing profile — alexmensch

alexmensch

HN member
Joined
Fri, Mar 16, 2012, 1:44 AM UTC
HN karma
32
Public activity
18 items

About alexmensch

Cofounder of Twingate and formerly product @ Dropbox

Recent public activity

  1. story
  2. comment
    Comment #26253197

    Hi Everyone! We launched Twingate on Show HN 6 months ago. Excited to share more about a concept we’re calling “Identity-First Networking” and a bunch of product enhancements & par…

  3. story
  4. comment
    Comment #23340336

    The most important factor in this decision is maintaining separation of concerns between user authentication (identity provider) and network authorization (Twingate). Since we rely…

  5. comment
    Comment #23332018

    Gotcha. In your example: nothing. We're okay with that. The level of security that results from the setup you described is what we are hoping Twingate will bring to people with con…

  6. comment
    Comment #23330965

    The client (the Twingate app on the user’s device) actually runs a transparent TCP proxy, so we’re just forwarding TCP payloads to the connector at the other end of the tunnel. Thi…

  7. comment
    Comment #23330182

    These are all valid points, and we’re keenly aware that trust is central to our offering. On the subject of trust, I’d love to get your take on my response to hlieberman’s comment …

  8. comment
    Comment #23329794

    Could you clarify a bit on "out of band" in this use case? In principle, if you have a way to access your bastion on a completely private--maybe physically separate / leased line--…

  9. comment
    Comment #23329588

    Our general approach is to rely on widely-used delegated trust mechanisms (eg. OAuth, SAML, CAs, etc.) and from our perspective the more of that we can do the better, as it helps d…

  10. comment
    Comment #23328851

    This is our very first public launch, and auditing/analytics are next up on our roadmap! Just to be clear, we do not currently and do not plan to intercept any traffic—any client a…

  11. comment
    Comment #23328605

    Hey, great question, and your setup seems very secure, but I’m sure it would be nice to reduce some of the overhead. The right way to support your ephemeral bastion use case with T…

  12. comment
    Comment #23328481

    Currently, yes, we’re focused on connecting users with services, but there’s nothing inherent to the underlying technology that prevents us handling service to service communicatio…

  13. comment
    Comment #23328052

    Totally! We've seen some nightmare configurations around separating dev/staging/prod environments involving scripts to change /etc/hosts back and forth and some funky VPN configura…

  14. comment
    Comment #23327889

    Good question! At the absolute limit, connectors are CPU-bound, but it's unlikely that you would hit a CPU limit before you exhaust all available file descriptors or network bandwi…

  15. comment
    Comment #23327632

    There are similarities in the general approach, but the two biggest differences between us and Teleport are: 1) We support native clients on every major platform (Mac, Windows, iOS…

  16. comment
    Comment #23327223

    Thanks! One of the things that we've really focused on is making Twingate super, super easy to deploy. From all of our customers conversations we've found that despite acknowledgin…

  17. comment
    Comment #23326764

    Hi everyone, I’m one of the cofounders of Twingate. Excited to share with the HN community what we’ve been working on over the last 18 months. Twingate is a modern solution for rem…

  18. story