I like Tailscale, but this reads as too self-aggrandizing. You have a mesh VPN product with some value-added services on top of it. That's great, but this idea isn't novel or unique. Why should your solution be the "new internet" instead of any of the alternatives? I wouldn't want to rely on a single company for all my internet infrastructure, anyway. So I'll stick with the traditional internet with all its complexit…
What's Tailscale's value prop? It's just a kludge together of various FOSS heavyweights..?
The New Internet
251–260 of 315 posts
Re: The New Internet
#252Tailscale complaining about centralized actors controling the internet, yet not allowing to sign up for Tailscale with your email but strictly requiring to use a Microsoft/Meta/Google account. Cant make this up.
You can use just about any OIDC. Some of the self-hosted options presented during sign up include Keycloak, Ory, Gitea, Zitadel, Authelia, and more. There's also a workaround to create a passkey account by signing up with any SSO provider, inviting yourself as an external user, accepting that invite and sining in with a passkey, then leave the original SSO network. Then you're not tied to any external service at all.
Re: The New Internet
#253Earlier quoted context omitted.
You can use just about any OIDC. Some of the self-hosted options presented during sign up include Keycloak, Ory, Gitea, Zitadel, Authelia, and more. There's also a workaround to create a passkey account by signing up with any SSO provider, inviting yourself as an external user, accepting that invite and sining in with a passkey, then leave the original SSO network. Then you're not tied to any external service at all.
Or, wild idea, just allow email signups like everyone else.
https://news.ycombinator.com/item?id=22760130
> (I'm a Tailscale co-founder) The idea is to avoid building yet another commercial service that holds onto your username and password. People have enough identities already. More details here: https://tailscale.com/blog/how-tailscale-works/ We know we keep getting feedback that people want a different way to authorize their accounts (especially for personal use), so we're looking at other options. We just really want to stay out of the username+password business; it's simply bad security practice.
Re: The New Internet
#254Earlier quoted context omitted.
Thanks for pointing this out. It's hard to communicate ipv4 and I dread even reading ipv6. I don't understand why they didn't just add two or four more fields to ipv4 e.g. 0.91.127.0.0.1 is localhost where 0.91 can be omitted in the local context. PS: I don't understand how networking works. Feels very very complex and full of jargons.
Because the fields are there for humans, in the packet itself it’s a 32bit integer, and you can’t just arbitrarily make the src/dest fields in the packet bigger— it stops being IPv4 then.
It's a fact of life that working with networking that we'll have to work with IP addresses at some level. It's easy to tell someone, "hey try typing in 'ping 8.8.8.8' and tell me what you get".
The readability of IPv6 is, in my opinion, worse with repeated symbols and more characters to remember. The symbols that were chosen were also poorly thought out. Colons are used in networking a lot of times when you want to connect to a service on a particular port, so if you want to visit 2001:4860:4860::8888 in your browser, you have to enclose the address in square brackets.
Re: The New Internet
#255> We’re removing layers, and layers, and layers of complexity, and making it easier to work on what you wanted to work on in the first place.
as an avid user, i'd say they are in fact adding more layers to the problem. it is well-designed and relatively accessible, sure, but it represents a stop-gap solution while everyone eventually pushes to the eventual solution.
it has always been the double-edged nature of abstraction. we give trust and responsibility to another party while for us networking works out "magically". but the moment your remote client has some auth issues, you snap back to reality. besides bandwidth costs, it seems that their otherwise generous pricing model is economically viable in post-ai landscape.
i'd personally like to act like a "landowner" of the internet, but currently being a rentor seems like a good idea while we all wait for social housing to finally get accepted.
Re: The New Internet
#256I think the author misdiagnoses the problem, and the proposed solution simply hides the centralization instead of removing it. The reason AWS is expensive is not because of IPv4, or the datacenters. It's mostly in their software/managed offerings, and the ability to quickly add more servers. If you are a "serious company" and you don't want to pay AWS or a similar company, renting a rack and colocating your own serve…
This rests on the incorrect assumption, pointed out in the post, that most applications need the kind of scale that warrants quickly scaling to more servers.
On other socials, a screenshot of the 'Not scaling' section is getting responses of "Those idiot developers think they need k8s scaling for their 1 req/s sites, ha ha."
The author brags about being able to (skip testing, CI/CD pipelines and just) edit their perl scripts (in prod,) really quickly.
What uptime is associated with that practice? As many 9's as it takes for Brad to debug his perl program in prod? This approach doesn't even scale to 2 developers unless they're sitting in the same room.
DevOps isn't a machine where you put unnecessary complexity in one end and get req/s out the other end. It's about risk and managing deployments better.
If I really wanted to engineer for req/s, I'd look at moving off k8s and onto bare metal.
Re: The New Internet
#257Earlier quoted context omitted.
>But most of 2024's network security problems originate from the devices behind your firewall getting exploited through their on requests, not some random shit connecting from the outside. That is Survivor Bias at its best. The originate _inside_ because NAT effectively blocks all _external_ requests.
> The originate _inside_ because NAT effectively blocks all _external_ requests. You mean the firewall effectively blocks all external requests.
The reason NAT works for this is because by default there are no Internet-accessible services available via the router. If a request is received by the router that doesn't match an open port, its OS will, by default, reject it, with no firewall required.
Re: The New Internet
#258Earlier quoted context omitted.
AFAIK, Zerotier is about equally proprietary, more-free (as in beer), and has been doing the node-to-node mesh thing instead of spoke-and-hub longer than Tailscale has been in existence. And if I remember correctly, ZT was initially created to provide something like this "New Internet" concept that Tailscale has apparently recently discovered, except they called it "Earth" and abandoned it in 2023. (Some things don't…
Tailscale does p2p, not hub-spoke, with additional DERP system which combines various NAT bypasses with worst case hair pinning over HTTPS - you can host all components yourself.
I didn't intend to leave to implication the fact that Tailscale is node-to-node, or that it is is not hub-and-spoke.
(I even had this up in a browser tab when I wrote that previous comment: https://tailscale.com/blog/how-tailscale-works)
Re: The New Internet
#259Earlier quoted context omitted.
So far as I’m aware, TailScale has been at all times a good actor. I have no problem criticizing tech companies, but I try to wait until they behave badly.
> TailScale has been at all times a good actor. This is the Cloudflare problem all over again. One day Matthew Prince will get hit by a bus, all the "trustworthy people" will leave, a PE firm will take the company private, and merge it with an ad network. Congrats, the entire internet now has a single companies ads all over it and we let it happen because we happened to like the people fucking us.
That's why people don't necessarily, and shouldn't, trust that Tailscale won't head down the same path. It's hard enough for non-profits - heck, the Mozilla Foundation is losing all the good will they've ever had, and even the Raspberry Pi Foundation decided to gaslight people when they started eyeing corporate money.
If there's an open source way to do a thing that's a pain in the ass and a way to do the same thing from a for-profit company, I'll take the pain in the ass thing every time. History has shown it to be the prudent thing time and time again.
Re: The New Internet
#260Earlier quoted context omitted.
> The originate _inside_ because NAT effectively blocks all _external_ requests. You mean the firewall effectively blocks all external requests.
You are technically correct that iptables is what provides the NAT functionality on Linux (by way of the MASQUERADE target), which many routers run. However, you are very incorrect that the firewall is directly involved in blocking the request. The reason NAT works for this is because by default there are no Internet-accessible services available via the router. If a request is received by the router that doesn't mat…
NAT is not required for any of the things you’re talking about.