Earlier quoted context omitted.
Someone is making your IT team do extra work without a good understanding of their systems if they're banning tailscale or granting special network level access thinking that ip or mac address based profiling is secure. Your network should be zero trust. That means you want to treat every host that connects as if it's on the public internet; the corollary to that is you should give your hosts access to the public int…
And then a few of those users who you treated like adults who don't need surveillance make a private network among themselves and other nodes in Russia and China to exfiltrate the corporation's most sensitive intellectual property, serve as a bridge for state-sponsored bad actors to bypass your firewall, and tunnel command-and-control traffic through your "unrestricted" egress, and now your zero-trust philosophy has…
Show HN: Netrinos – A keep it simple Mesh VPN for small teams
31–40 of 75 posts
Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#32The "No IT Department" part of your marketing immediately turns me off because that's actively encouraging "shadow IT". We all get that sometimes companies have IT policies which are outdated and get in the way, but that's a problem for someone up the chain to solve. A team or department deciding to just start doing their own thing with something like this which isn't managed by or even known about by the official co…
Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#33Naive question here: with WireGuard VPN, does all traffic route through the VPN or only those packets bound for the other devices in the mesh?
WireGuard itself can be configured to work either way. Our target market is smaller teams and people with limited IT skills. So, we chose not to send all traffic through the vpn. The only traffic going through the VPN is traffic to and from your other devices (in your account). Internet access is still through your default network. In the Pro version, you can route specific destinations through other peers, also belo…
Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#34The obvious competitor here is Tailscale. But let's say, reasons, and Tailscale isn't an option. Then you go down the path... TwinGate, Teleport, Netbird, Pomerium, Netmaker, ZeroTier, etc...
Even the initial pricing and free tier are you're up against are going to mostly be a deal breaker compared to what's out there.
Trusting a VPN provider is a lot. If you're running the control plane - why should I trust Netrinos?
Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#35Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#36Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#37The "No IT Department" part of your marketing immediately turns me off because that's actively encouraging "shadow IT". We all get that sometimes companies have IT policies which are outdated and get in the way, but that's a problem for someone up the chain to solve. A team or department deciding to just start doing their own thing with something like this which isn't managed by or even known about by the official co…
Think of an SMB where you might know you need to do something (like connect a new store location to the server in your main location’s closet), but don’t know how or can’t afford to hire an IT person full time. This is probably the main market for this. Then once you get more buy in, experience, and reputation, this VPN could stay to see larger clients. That’s at least how I’d expect to see this grow.
Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#38Earlier quoted context omitted.
Someone is making your IT team do extra work without a good understanding of their systems if they're banning tailscale or granting special network level access thinking that ip or mac address based profiling is secure. Your network should be zero trust. That means you want to treat every host that connects as if it's on the public internet; the corollary to that is you should give your hosts access to the public int…
And then a few of those users who you treated like adults who don't need surveillance make a private network among themselves and other nodes in Russia and China to exfiltrate the corporation's most sensitive intellectual property, serve as a bridge for state-sponsored bad actors to bypass your firewall, and tunnel command-and-control traffic through your "unrestricted" egress, and now your zero-trust philosophy has…
Network controls alone don’t stop exfiltration. HDMI/DP can move data faster than most consumer NICs. Does the system account for that scenario?
Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#39Well, I wish you the best with this - but I really don't understand the target market. The obvious competitor here is Tailscale. But let's say, reasons, and Tailscale isn't an option. Then you go down the path... TwinGate, Teleport, Netbird, Pomerium, Netmaker, ZeroTier, etc... Even the initial pricing and free tier are you're up against are going to mostly be a deal breaker compared to what's out there. Trusting a V…
Re: Show HN: Netrinos – A keep it simple Mesh VPN for small teams
#40Well, I wish you the best with this - but I really don't understand the target market. The obvious competitor here is Tailscale. But let's say, reasons, and Tailscale isn't an option. Then you go down the path... TwinGate, Teleport, Netbird, Pomerium, Netmaker, ZeroTier, etc... Even the initial pricing and free tier are you're up against are going to mostly be a deal breaker compared to what's out there. Trusting a V…