Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
11–20 of 90 posts
Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#12I'm curious how you guys are competing with the other folks in the space. WARP was/is a really tough product to maintain (crossplatform networking is very difficult). CF was doing well with WARP mostly due to the distribution advantage. I imagine it's harder for startups to break into the space.
Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#13Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#14I don’t really get the threat model of these “zero trust” appliances and how they are really different from a VPN. Can someone explain it to me? It still looks very much like a perimeter.
If you remember NAC products from back in the day (policy-driven 802.1x and filtering, all designed to deal with the "chewy center" problem), this is like the overlay network version of that, and because it's all software it's much easier to deploy and manage.
Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#15Hey! I worked on WARP at Cloudflare. I believe Cisco has anyconnect and then there's zscaler. I'm curious how you guys are competing with the other folks in the space. WARP was/is a really tough product to maintain (crossplatform networking is very difficult). CF was doing well with WARP mostly due to the distribution advantage. I imagine it's harder for startups to break into the space.
We're trying to stay focused on keeping policies easy to define and manage so that access management is... manageable as you scale. That and the fact data doesn't go through the cloud / intermediary have been a couple of the reasons customers say they prefer us.
Definitely an exciting space to be building in!
Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#16For a small example, when working from home, we want to connect to SMB shares over the vpn, with regular traffic going over the regular LAN interface of the computer. When the same person comes into the main office, just use the LAN. The simplest solution is to teach users to make sure they turn their VPN off when in the office, but that’s a super easy step to forget.
Could Firezone help managing these quality-of-life details for end users?
Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#17One of the pain points I’ve experienced with configuration of traditional VPNs is when devices physically connect to different parts of the network when staff travel between home and different offices. For a small example, when working from home, we want to connect to SMB shares over the vpn, with regular traffic going over the regular LAN interface of the computer. When the same person comes into the main office, ju…
Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#18I don’t really get the threat model of these “zero trust” appliances and how they are really different from a VPN. Can someone explain it to me? It still looks very much like a perimeter.
It's a "virtual" or "overlay" central reference monitor for the whole network --- imagine collapsing an entire campus network down to a single firewall --- which makes it really easy to draw arbitrary internal perimeters. The real customers for these products all tend to have group-based policies. If you remember NAC products from back in the day (policy-driven 802.1x and filtering, all designed to deal with the "che…
Re: Launch HN: Firezone (YC W22) – Zero-trust access platform built on WireGuard
#19I'm a big fan of Tailscale but it's unfortunate that it's proprietary, so it's really nice to see an open source alternative. The commercial pricing also looks very reasonable. Wishing your product much success.