Live data from Hacker News

Netbird – Open Source Zero Trust Networking

netbird.io

191–200 of 299 posts

Re: Netbird – Open Source Zero Trust Networking

#191

Earlier quoted context omitted.

Your arbitrary, loosely-detailed complaints would apply to literally everyone, every app. It's on f-droid, it's open source, you're being ridiculous. I'm not even sure you understand what you're asking for. The official, open source Tailscale client explicitly supports headscale servers.

It's the only app from the ones I use that my friends and relatives who already use iOS can't even install due to geoblocking. If you don't see it as a problem means you're not affected and perhaps lack some empathy. Yes, I understand the Apple ecosystem is a problem. But it's not an insurmountable one. Builds of Free Software exist on Apple Appstore and none of them exhibit this problem, unless they are tied to a co…

[deleted]

Re: Netbird – Open Source Zero Trust Networking

#193
I have tried multiple different solutions of so called "zero trust networking". My personal favourite one is Netbird but.. it lacks one feature: switching between multiple setups (networks). I am helping to maintain some startups and it would be just nice to quickly change (or even better: have access to multiple at once!) networks.

Re: Netbird – Open Source Zero Trust Networking

#195
For the guys at Netbird, please create an entry in the https://wiki.nixos.org explaining how to use it with nixos.

- Tailscale has one entry - Pangolin is getting one

I would like to see, even if brief:

1. Getting started

2. Hardware requirements

3. Security considerations

4. Recommended architecture, like running in a VPS if it makes sense

5. Configuring a server

6. Configuring devices

7. Resources (links to read more on netbird)

Thank you from the home lab community

Re: Netbird – Open Source Zero Trust Networking

#196
post #193

I have tried multiple different solutions of so called "zero trust networking". My personal favourite one is Netbird but.. it lacks one feature: switching between multiple setups (networks). I am helping to maintain some startups and it would be just nice to quickly change (or even better: have access to multiple at once!) networks.

> it would be just nice to quickly change (or even better: have access to multiple at once!) networks.

Accessing multiple corporate networks simultaneously from the same endpoint violates all sorts of access policies. If it doesn’t, the access policy is lacking. Even for startups.

And no, unless you build it and enforce it from the start, no one ever succeeds in bolting on a reasonably security posture after implementing all their other processes no one will dare touch.

Re: Netbird – Open Source Zero Trust Networking

#197

Earlier quoted context omitted.

Your arbitrary, loosely-detailed complaints would apply to literally everyone, every app. It's on f-droid, it's open source, you're being ridiculous. I'm not even sure you understand what you're asking for. The official, open source Tailscale client explicitly supports headscale servers.

It's the only app from the ones I use that my friends and relatives who already use iOS can't even install due to geoblocking. If you don't see it as a problem means you're not affected and perhaps lack some empathy. Yes, I understand the Apple ecosystem is a problem. But it's not an insurmountable one. Builds of Free Software exist on Apple Appstore and none of them exhibit this problem, unless they are tied to a co…

I guess I'll just say that I hope you share the blame with the appropriate parties whenever you are suffering through iOS entitlements and provisioning to publish or self-load it on your iPhone, since Netbird's iOS client is open source.

Though, maybe it's not doing business in the US, and maybe the app is not similarly geo-blocked.

Actually can you not just pull the app and then side-load it anyway? That's what I would do if I couldn't get Tailscale from the Play Store...

Maybe this comment helps shed light on who I think are real the cause of your ire. Frankly I strongly agree with Brad's comment on why they don't care to open source the iOS client like they do the Android one.

Re: Netbird – Open Source Zero Trust Networking

#198
post #126
post #114

Earlier quoted context omitted.

Tailscales founders are Canadian, principled, and are very sensitive to Canadian needs. I very much trust Avery and team to do what’s necessary to keep US hands off the data. edit: someone pointed out they’ve signed new users on to a US co. 15 months ago. I made the statement without knowing this. they aren’t as capable as I originally claimed.

According to their ToS all customer accounts registered on or after September 3, 2024 are signed on to a US company, so no they're not doing what's necessary to keep US hands off the data.

Thanks, good spot indeed. Just emailed our AM to find out what the situation is.

Re: Netbird – Open Source Zero Trust Networking

#199
I was previously using headscale and was finding it a bit finicky. Recently switched to self hosted netbird and its been great so far. However, if the Netbird teams sees this, please implement a built-in updater for the client apps! needing to download and install the package again is a bit annoying

Re: Netbird – Open Source Zero Trust Networking

#200
post #144
post #77

Earlier quoted context omitted.

I've used it for some time, it feels very much like it is in maintenance mode. You manage a PKI and have to distribute the keys yourself, no auth/login etc. it's much better than wireguard, not requiring O(N) config changes to add a node, and allowing peoxy nodes etc. iirc key revocation and so on are not easy.

This problem has been brought up in the OpenZiti community many times. I like Nebula, but it's not 'truly open source'.

What do you mean?
Post reply on HN