Live data from Hacker News

Tailscale has reached general availability

tailscale.com

81–90 of 128 posts

Re: Tailscale has reached general availability

#81
post #79
post #17

Earlier quoted context omitted.

Even if it is only as innocent as having your friends mass upvoting every thread of yours, then this is an outright exploitation of HN rules. Again never happened that a company, especially a company that was started a few months ago and hardly known by anybody, gets to the frontpage with a 100% hit rate for more than 10 times in less than 3 months.

Sure, that's very much against HN's rules. Also against HN's rules is posting accusations about these things without evidence. I've looked extensively into these cases, mainly because you've drummed up such a fuss about them with your various accounts. I found zero evidence of abuse. All the data indicates that these threads have been upvoted by serious, longstanding HN community members are just genuinely interested…

There is no accusation, you're just playing with words to deflect the situation and make it on me instead on the real issue here which is about a company that had more frontpage posts of free positive publicity than most FAANG companies in the last month with a staggering 100% hit rate.

Re: Tailscale has reached general availability

#82
post #8
post #5

Earlier quoted context omitted.

(I'm a Tailscale co-founder) The idea is to avoid building yet another commercial service that holds onto your username and password. People have enough identities already. More details here: https://tailscale.com/blog/how-tailscale-works/ We know we keep getting feedback that people want a different way to authorize their accounts (especially for personal use), so we're looking at other options. We just really want…

Since it's mostly tech-savvy people here that want something else and I'm assuming it's an oauth process, perhaps github and/or gitlab?

Github's on the list to support, yeah. We can speak most "identity provider" protocols these days (OAuth, OIDC, SAML, etc.), but it's this weird little universe: the protocols are meant to let you implement once to support everyone, but in practice every IdP has its own little idiosyncrasies that mean you need a little bit of dedicated code for each new IdP. So, we end up with a backlog of "support IdP X, which is ostensibly OAuth but does something strange we've never seen yet" :)

Re: Tailscale has reached general availability

#83
post #52
post #10

I will get banned for this in a matter of minutes but I will say the truth to whoever think HN is fair. For the past 3 months, every, again EVERY post that was linked to Tailscale (not just the company domain but also the blog posts of the founders' websites), has gotten to the frontpage within minutes, with a full 100% hit rate. This cannot happen for any company, any project or anything else to be honest since ther…

I haven't been offended by it, and I'm the founder of a company that's been around longer and is probably the closest competitor: https://www.zerotier.com/ I don't hate on people for doing similar things. If anything I am absolutely shocked it took someone this long, since to me the idea of a full mesh virtual network is how things should work, everything else is stupid and clunky, the fact that we have to bounce off…

> I am absolutely shocked it took someone this long

Because it's really hard to monetize it. Speaking from the experience.

Edit - This particular bicycle gets reinvented on regular basis and in a nearly identical form. While technical details are difficult, the overall idea is rather simple. Rendezvous servers to coordinate the setup and NAT traversal + relays to handle the edge cases. The tricky part is the UX... but it's still nothing compared to monetization. Very few end users will pay for this, because if it "just works", it doesn't look like something worth paying for. Smaller companies will pay, but they don't realize they need it. Larger companies realize the need, but they won't touch 3rd party managed VPNs with a long pole. It's really quite a pickle. But the tech is beautiful :)

Re: Tailscale has reached general availability

#86
post #64
post #10

I will get banned for this in a matter of minutes but I will say the truth to whoever think HN is fair. For the past 3 months, every, again EVERY post that was linked to Tailscale (not just the company domain but also the blog posts of the founders' websites), has gotten to the frontpage within minutes, with a full 100% hit rate. This cannot happen for any company, any project or anything else to be honest since ther…

> Thank you HN for proving me right You've been proven nothing of the sort. I buried your post and the submission itself while investigating this claim, even though you've been trolling HN threads with these rants for weeks now, using multiple accounts to do it, ignoring our requests to stop breaking the site guidelines, and barraging us with ranty emails to boot. I've looked closely at the data and found no evidence…

I want to add something for fair-minded users who may still be wondering, after all that, whether the interest in the OP really is organic or whether there might be shenanigans. It's natural to worry about this, especially because other users tend to make loud and grand claims about abuse, whether they have knowledge or not.

You can check a lot of this for yourself using publicly available information.

Look at a sample of users who've been expressing interest about Tailscale, in threads about that topic and/or Wireguard or other topics. Check out the histories of these users—you can do that by clicking on a username to go to their profile, and then clicking on 'comments' or 'submissions'. You'll see that most are longstanding, serious community members. If your random samples look anything like the ones I've examined, you'll find many excellent HN contributors among them, with a lot of technical expertise. This is evidence that the interest in this topic is both organic and serious. I'd supply links, but it wouldn't feel right to haul in specific usernames that way. It's easy enough to check.

To that public information, I can add some non-public facts. First, the profiles of users upvoting these threads look much the same as the commenters. Of course in many cases they are the same, since it's natural to both upvote and comment on something that you find interesting. In addition, the voting patterns on these threads look like what we see on popular topics of organic interest, and nothing like what we tend to see with voting rings and organized promotion.

Conclusion: although we can never say for sure, because we aren't inside users' heads while they upvote, the evidence points to organic interest. I'll go further: I'm the person who has spent by far the most time on this problem in the history of HN and I find it hard to imagine the evidence being any clearer. Also, no one at HN (and no one at YC that I know of) has any connection with any of the people involved in this project. I've spent so much time writing about this because (a) I don't like to see people smeared, (b) we take concerns about abuse of HN extremely seriously, and (c) I want a record to link back to in the future so I don't have to spend any more sad hours on this.

Re: Tailscale has reached general availability

#87

Earlier quoted context omitted.

It's easy to make a basic password login system, and very technical people use password managers, long passwords, etc. But there's a long "tail" (ha ha) of people who don't use long passwords, who will reuse their password on multiple web sites, who will forget their password and need to recover it using their mother's maiden name, etc. This opens up unlimited opportunity for phishing attacks. And you don't get any k…

> few very technical people use password managers, long passwords, etc I'd be very surprised if this was true. Most all technical (competent) people I know use a pw manager of some sort

I know only myself and one other person using a password manager, even though I know a lot of technical folks.

Re: Tailscale has reached general availability

#88
post #52

Earlier quoted context omitted.

I haven't been offended by it, and I'm the founder of a company that's been around longer and is probably the closest competitor: https://www.zerotier.com/ I don't hate on people for doing similar things. If anything I am absolutely shocked it took someone this long, since to me the idea of a full mesh virtual network is how things should work, everything else is stupid and clunky, the fact that we have to bounce off…

> I am absolutely shocked it took someone this long Because it's really hard to monetize it. Speaking from the experience. Edit - This particular bicycle gets reinvented on regular basis and in a nearly identical form. While technical details are difficult, the overall idea is rather simple. Rendezvous servers to coordinate the setup and NAT traversal + relays to handle the edge cases. The tricky part is the UX... bu…

I disagree. It is challenging to monetize, but so are many other things.

I'll give what I think are my reasons:

- It's "easy" to do a proof of concept here, but it's brutally hard to make it really work well and at scale. There are a lot of buggy NATs, highly restrictive firewalls, etc. Network virtualization, which is what you need for it to be general purpose rather than app specific, is another layer of difficulty.

- It's hard to do it securely. Anything that gets popular will get attacked a lot and has to stand up against that. It's easier to secure centralized systems against most attacks for multiple reasons.

- The dominant paradigmatic fads from 2004-2019(ish) were cloud and mobile. Cloud obviates the need for this (in exchange for all privacy and freedom), while early mobile devices and mobile data options were too wimpy to do P2P. The latter is still a problem but less so today than 5-10 years ago.

- Most P2P software has had poor usability, slowing its adoption.

- The cryptocurrency bubble sucked all the air out of the decentralization room, causing the entire notion of P2P and decentralization to get conflated with CoInZ. That seems to be ending.

Re: Tailscale has reached general availability

#89

Do you plan to release a Terraform provider for configuring Tailscale?

(Tailscale employee here) Automatic provisioning is definitely on the list. It's an enabler for immutable infra deployment, getting connectivity into containers, and building things like automatic enrollment based on external sources of trust (e.g. "automatically enroll any VM that can prove via its vTPM that it's in this GCP account").

Re: Tailscale has reached general availability

#90
post #65

Can you use tailscale with friends or does it only work with the same email address?

(Tailscale employee here) For personal use, we're planning a "sharing" feature, so that you can share machines (or individual services) with friends, and they just show up on their network (after mutual approval, of course). It's a feature I very much want for my personal use of tailscale, so it's going to happen :)
Post reply on HN