Live data from Hacker News

The New Internet

tailscale.com

241–250 of 315 posts

Re: The New Internet

#241
post #231

Earlier quoted context omitted.

Honestly, I kind of missed Hamachi in the last decades. It was such a superb and easy to use tool to design/configure your own private networks at the time. Filesharing, local game LANs, development cooperation, heck, even media streaming was so easily done at the time. Personally I think that the future of peer to peer isn't tailscale, it's more someting along the lines of a selfhosted hamachi variant that's able to…

That sounds a lot like Headscale.

The issue I have with tailscale/headscale is that its focus isn't being an end user app that people can start on demand.

Hamachi was different because a child could use it (literally). It was designed like an instant messenger, and you could easily create groups and invite friends for a LAN party. No IP masks, no hashes, none of that complicated stuff was necessary.

I'd only see maybe a tool that was built on top of headscale that could do that, but headscale's focus is too far off for something like that, and in my opinion too low level.

Re: The New Internet

#242
post #161

Earlier quoted context omitted.

> Who was stopping anyone from doing it then, and who is stopping anyone from doing it now? The folks who either (a) got in early on the IPv4 address land rush (especially the Western developed countries), or (b) with buckets of money who buy addresses. If you're India, there probably weren't enough IPv4 address in the first place to handle your population, so you're doing IPv6: * https://www.google.com/intl/en/ipv6/…

There is another reason: the addresses are long and impossible to remember and hard to type. I always bring this up and it’s always dismissed because tech people continue to dismiss usability concerns. Even “small” usability differences can have a huge effect on adoption.

That’s because nobody normal— anyone who isn’t a tech person— remembers IP addresses.

Hell I can’t get tech people I work with to give me their public IP.

Re: The New Internet

#243
I love this.

Except to use tailscale you do need to bring in a while OIDC authentication provider.

It's all small and aimed at avoiding scale until the very first step, when suddenly only the big complex thing is acceptable.

I still just want to just use my email and a top. The only one of the auth providers tailscale supports that I have is GitHub, but I don't use GitHub as beyond work as I self host my git.

When the onboarding is "maintain and run a full oidc provider", all we've done is trade one aspect of complexity for another.

Re: The New Internet

#244
Tailscale complaining about centralized actors controling the internet, yet not allowing to sign up for Tailscale with your email but strictly requiring to use a Microsoft/Meta/Google account. Cant make this up.

Re: The New Internet

#245

Earlier quoted context omitted.

So far as I’m aware, TailScale has been at all times a good actor. I have no problem criticizing tech companies, but I try to wait until they behave badly.

> I have no problem criticizing tech companies, but I try to wait until they behave badly. I'd rather not wait until they have a (quasi-)monopoly on something though. Twitter was great until…

when was twitter ever great? It has been creating echo chambers from day one, and deliberately making discourse difficult and non-nuance. It's arguably the shittiest form of human communication, and that counts facebook also.

Re: The New Internet

#246

Tailscale complaining about centralized actors controling the internet, yet not allowing to sign up for Tailscale with your email but strictly requiring to use a Microsoft/Meta/Google account. Cant make this up.

You can use just about any OIDC.

Some of the self-hosted options presented during sign up include Keycloak, Ory, Gitea, Zitadel, Authelia, and more.

There's also a workaround to create a passkey account by signing up with any SSO provider, inviting yourself as an external user, accepting that invite and sining in with a passkey, then leave the original SSO network. Then you're not tied to any external service at all.

Re: The New Internet

#247

Earlier quoted context omitted.

> Also, NAT is desirable for security/network isolation reasons […] This is security theatre. People have been saying that NAT is not a security feature for over a decade: * https://blog.ipspace.net/2011/12/is-nat-security-feature/ but the message still has not sunk in. The "Zero Trust" paper was published by John Kindervag in 2010: * https://media.paloaltonetworks.com/documents/Forrester-No-Mo... Most modern attacks…

> https://blog.ipspace.net/2011/12/is-nat-security-feature/ >>Basic NAT (as defined in RFC 2663) performs just the IP address translation (one inside host to one IP address in the NAT pool). The moment the inside host starts a session through the NAT, it becomes fully exposed to the outside world. This is a lie. A "session through the NAT" does not really expose the host to the outside world, because in 99% of the ca…

> This is a lie. A "session through the NAT" does not really expose the host to the outside world, because in 99% of the cases this is a TCP session, and the NAT machine would drop all "out of order" packets.

No, it's not. NAT only translates addresses and does not inspect the TCP "internals" (like sequence number etc, which would allow it to block certain packets).

What you are describing is a stateful firewall that allows "reply packets" for an established TCP-session.

Re: The New Internet

#248

Earlier quoted context omitted.

>at least one member who can run a server It may be highly unlogical, but maybe by shooting for zero it would be possible to bat 1000? I do everything it takes so that the "extended family" site just works after I leave, as long as the "operator" can keep track of their USB sticks. Scrap PCs being used as media servers have no internal drive. Boots to the stick containing the server app. Accesses media on a second st…

A medieval castle could be defended by surprisingly few people, but not by zero people . And a castle full of people who don't know how to fortify and maintain its defenses eventually becomes someone else's castle. Aiming for zero required sysadmins in the short term after your own passing, I think the computers you leave behind will run into a similar case of the same general problem in the long term: there's no suc…

You have hit the nail on the head.

Especially with passing, eventually it's like the siege of the Alamo, when the walls do end up breached there's not a soldier there that can do any good.

It's shoestrings anyway and amazing it's working for now :)

Re: The New Internet

#249
post #63

Earlier quoted context omitted.

> Can anyone elighten me regarding what is different or special about 100.64.0.0/10 vs say, 192.168.0.0 or 10.0.0.0. A bit of context: if an ISP cannot get enough IPv4 addresses for the WAN-side of people's home routers, some problems exist: * something in 192.168/16 is generally used for the LAN-side of people's home routers, so that cannot be used on the WAN side * 10/8 is used for business/enterprise corporate net…

Interesting, I thought docker uses 172.*.

…and it’s a perfect display of the technical competence of Docker Inc. :) they do stuff like that, in all kinds of domains, all the time.

Re: The New Internet

#250
I'll preface this by saying: I DO appreciate tailscale and what they've done for frictionless VPNs; I use it daily. But this post has a really unfortunate tone, it comes across as really arrogant. Not ambitious, but arrogant. The notion that the population as a whole is buying tailscale because it might offer some as-yet unpublished capabilities at some non-determinant point in the future... is delusional. And tailscale's moat is very shallow - yes, there's some nifty networking stuff going on, but it's well understood and the functionality will be replicated by competitors as tailscale gains mainstream traction, however big their warchest is.
Post reply on HN