Live data from Hacker News

The New Internet

tailscale.com

221–230 of 315 posts

Re: The New Internet

#221
post #9

I love Tailscale, but this post gives me the creeps. The internet succeeded because it was built on standards and was completely free. With Tailscale, I get wireguard is open source and we have things like Headscale. But the whole everyone gets an IP, doesn’t it depend on Tailscale owning a massive ip address space? We can all wait until full ipv6 rollout, or we can depend on centralized ipv4, and servers and proprie…

If you had to move off of tailscale, what would you move to?

NetBird is a promising option. OpenZiti is another. ZeroTier hasn't evolved much, IMHO. Would also love to see someone breathe new life into https://github.com/omniedgeio/omniedge

Re: The New Internet

#222
post #207
post #161

Earlier quoted context omitted.

There is another reason: the addresses are long and impossible to remember and hard to type. I always bring this up and it’s always dismissed because tech people continue to dismiss usability concerns. Even “small” usability differences can have a huge effect on adoption.

Also, NAT is desirable for security/network isolation reasons, and having no distinction between a local IP and a public IP has a lot of disadvantages. Yes, there are ways to configure IPv6 to isolate subnets, separate local traffic from internet traffic, set up firewalls and DMZs, run local DNS, etc., but they're all more complicated to configure and administer than their IPv4 equivalents.

Modern ransomware attacks has demonstrated beyond doubt the very harmful belief that private network behind nat is an acceptable alternative to keeping systems secured and patched. The only thing nat does in a security sense is to provide false sense of security until the day a single machine inside get compromised and then the whole hospital or company comes to a standstill while rushing to restore from backup, praying that they do keep backups. Its a mistake, and the only reason it felt like a good idea was because Microsoft with windows 98/2k/xp got hit en-mass with worms targeting vulnerable windows machines that never got updates.

Re: The New Internet

#223

As I've been deliberately moving toward self-hosted computing, under my control, on my home network , I've had a feeling more and more that we're on the cusp of something transformative... For those who want it and those who care. There's an ecosystem of mostly FOSS software now designed to run on a home network and replace big, centralized, cloud providers. That software is right on the edge of being easy enough for…

What are the hard parts of hosting from home? What solutions have you been using?

Re: The New Internet

#224
post #207

Earlier quoted context omitted.

Also, NAT is desirable for security/network isolation reasons, and having no distinction between a local IP and a public IP has a lot of disadvantages. Yes, there are ways to configure IPv6 to isolate subnets, separate local traffic from internet traffic, set up firewalls and DMZs, run local DNS, etc., but they're all more complicated to configure and administer than their IPv4 equivalents.

> NAT is desirable for security/network isolation reasons For the love of expletive this mistaken belief needs to have died yesterday. NAT boxes help primarily because they also contain a firewall. But most of 2024's network security problems originate from the devices behind your firewall getting exploited through their on requests, not some random shit connecting from the outside. (Yes, that does still happen, so y…

Amen! In the 2000s I had a newly setup windows xp with the modem on the internet. After 30 minutes it was toast.

Riddled with viruses.

Re: The New Internet

#225
post #207

Earlier quoted context omitted.

Also, NAT is desirable for security/network isolation reasons, and having no distinction between a local IP and a public IP has a lot of disadvantages. Yes, there are ways to configure IPv6 to isolate subnets, separate local traffic from internet traffic, set up firewalls and DMZs, run local DNS, etc., but they're all more complicated to configure and administer than their IPv4 equivalents.

> Also, NAT is desirable for security/network isolation reasons […] This is security theatre. People have been saying that NAT is not a security feature for over a decade: * https://blog.ipspace.net/2011/12/is-nat-security-feature/ but the message still has not sunk in. The "Zero Trust" paper was published by John Kindervag in 2010: * https://media.paloaltonetworks.com/documents/Forrester-No-Mo... Most modern attacks…

>https://blog.ipspace.net/2011/12/is-nat-security-feature/ >>Basic NAT (as defined in RFC 2663) performs just the IP address translation (one inside host to one IP address in the NAT pool). The moment the inside host starts a session through the NAT, it becomes fully exposed to the outside world.

This is a lie. A "session through the NAT" does not really expose the host to the outside world, because in 99% of the cases this is a TCP session, and the NAT machine would drop all "out of order" packets.

>Most modern attacks start from a compromised internal host (e.g., from phishing), or through stolen credentials via a remote access method.

Your statement is a perfect example of https://en.wikipedia.org/wiki/Survivorship_bias.

Most modern attacks start from an internal host exactly because NAT makes external attacks infeasible for the majority of scenarios.

>Set your firewall to default deny, then add a rule for allow outgoing connections, followed by only allow incoming connections if they are replies.

What about I don't do it, and the system is still _automatically_ secure, because NAT does exactly that while being _required_ for the system to work.

>See Figure A-5

LOL. What about I don't see any figures, and the system still works and is secure for the 99% of the cases.

Re: The New Internet

#226
post #207

Earlier quoted context omitted.

Also, NAT is desirable for security/network isolation reasons, and having no distinction between a local IP and a public IP has a lot of disadvantages. Yes, there are ways to configure IPv6 to isolate subnets, separate local traffic from internet traffic, set up firewalls and DMZs, run local DNS, etc., but they're all more complicated to configure and administer than their IPv4 equivalents.

> NAT is desirable for security/network isolation reasons For the love of expletive this mistaken belief needs to have died yesterday. NAT boxes help primarily because they also contain a firewall. But most of 2024's network security problems originate from the devices behind your firewall getting exploited through their on requests, not some random shit connecting from the outside. (Yes, that does still happen, so y…

>But most of 2024's network security problems originate from the devices behind your firewall getting exploited through their on requests, not some random shit connecting from the outside.

That is Survivor Bias at its best.

The originate _inside_ because NAT effectively blocks all _external_ requests.

Re: The New Internet

#227
post #186

Earlier quoted context omitted.

> There is another reason: the addresses are long and impossible to remember and hard to type. If only there was some mechanism in which we could use a human-friendly label and have that translated to a computer-usable address… > I always bring this up and it’s always dismissed because tech people continue to dismiss usability concerns. I don't bother remembering IPv4 addresses, so I'm not sure why I would bother to…

> who remembers them nowadays? 0118 999 881 999 119 725… 3 Me, that’s the new number for the emergency services. Actually, that’s the only phone number I can remember :D

  Eight six seven five three oh nine
  Eight six seven five three oh nine

Re: The New Internet

#228
post #15

An incredibly long ramp up to complaining about centralised control by rent seekers (a very reasonable complaint!) which gets bogged down in some ostensibly unrelated shade about whether client-server computing makes sense (it does) or is itself somehow responsible for the rent seeking (it isn't; you can seek rent on proprietary peer to peer systems as well!) to then arrive at: > There’s going to be a new world of ha…

Honestly, I kind of missed Hamachi in the last decades.

It was such a superb and easy to use tool to design/configure your own private networks at the time. Filesharing, local game LANs, development cooperation, heck, even media streaming was so easily done at the time.

Personally I think that the future of peer to peer isn't tailscale, it's more someting along the lines of a selfhosted hamachi variant that's able to put generically nodes together from all across different NATs and ASNs, generically understanding NAT breaking techniques and STUN/TURN/turtle routing.

A tool like this that could also allow remote users to chime in without a centralized VPN gateway would be a killer feature for the modern world.

Re: The New Internet

#229

Earlier quoted context omitted.

So far as I’m aware, TailScale has been at all times a good actor. I have no problem criticizing tech companies, but I try to wait until they behave badly.

Wouldn't the point be they're an indecent, possibly bad, actor by default since they're a business at all rather than just creating or contributing to protocols/standards to resolve the issues their product relies on to exist? The only way they could be a good actor is if they're using the money from their sales to fund that initiative with a plan to obsolete themselves. I suppose if you follow that thread though a l…

BTW the best way to make standards happen is to sell a product based on the standard. Academic standards don't go anywhere.

Re: The New Internet

#230

Earlier quoted context omitted.

> NAT is desirable for security/network isolation reasons For the love of expletive this mistaken belief needs to have died yesterday. NAT boxes help primarily because they also contain a firewall. But most of 2024's network security problems originate from the devices behind your firewall getting exploited through their on requests, not some random shit connecting from the outside. (Yes, that does still happen, so y…

>But most of 2024's network security problems originate from the devices behind your firewall getting exploited through their on requests, not some random shit connecting from the outside. That is Survivor Bias at its best. The originate _inside_ because NAT effectively blocks all _external_ requests.

> The originate _inside_ because NAT effectively blocks all _external_ requests.

You mean the firewall effectively blocks all external requests.

Post reply on HN