Live data from Hacker News

Tailscale raises $100M

tailscale.com

201–210 of 468 posts

Re: Tailscale raises $100M

#201
post #97
post #81

Earlier quoted context omitted.

I thought that Tailscale was pretty interesting. Avery Pennarun, its CTO, is somebody whose judgment I am used to trusting. Then I learned that to use it, I would be dependent on authenticating using a login on one of the unaccountable internet behemoths who could take away my account for any random reason or no expressed reason at all. No, thank you.

If you use an identity provider like Okta or OneLogin, then you're not tied to any "contentful" services like GitHub or a Google account that "historically" seem to have more problems of this type. As far as threat models go, I can't really say I understand this one too much.

Okta and OneLogin are both private corporations that have each existed for 13 years. Does your threat model include an estimate for how long they will stay in business? What if one of them puts the other out of business? Does your threat model choose a winner in that fight?

As far as paid services the possibility also is there that someday _you_ run out of money and have to stop paying them. They tend to shut down your access when that happens. Another financial threat you have to model.

These things don't happen when you use public key authentication.

Re: Tailscale raises $100M

#202
post #193

Funding scares me. It bring sharks onboard who do not share the same vision. They will demand revenue and ROI above all else. I like Tailscale but I hate this business model down to the core (Netlify as an example). Tailscale was doing fine as it was, capable people there already. It quickly became an "exit type of business", too quickly. These companies usually bring something really easy to use, let people onboard…

> They will demand revenue and ROI above all else.

I don't think this is true. They mostly demand growth over all else.

Re: Tailscale raises $100M

#203

Earlier quoted context omitted.

> Yeah, no one is going to allow unsolicited inbound connections even without NAT so you still have to have something to hook up the two ends in a P2P setting. Sure they are. All home routers that I'm aware of allow for port forwarding so folks can self-host a service: perhaps a game server (e.g., Minecraft), web, e-mail, etc. It's just going forward you can set up a separate subnet to put your gear in (especially if…

... if your definition of "home routers" excludes ISP-provided ones, then I'll agree. Unfortunately, I'm pretty sure that either you are on an ISP that actually cared and found a good supplier or didn't check out what are the capabilities of ISP-provided routers.

Of the three ISPs in my area that I have used, all of them allowed inbound traffic and either had useful controls in their routers or didn't supply a router, just an ethernet handoff. RCN, Comcast, Verizon.

All of them filtered out the SMB/CIFS ports.

Two of them filtered outbound port 25; one of them was willing to open it with the additional cost of a static IP.

Re: Tailscale raises $100M

#204
post #49

Earlier quoted context omitted.

Indeed, 1Password is practically a utility at this point, as far as I'm concerned. I really like the direction they're heading and they're solving some pretty tricky problems without compromising on security, predominantly in the enterprise domain. The experience is the same regardless of whether you're an enterprise user or a personal or family user. It's polished enough that my grandma can use it.

> I really like the direction [1Password] is heading I thought customers were complainingly loudly against their new direction of making 1Password an Electron app. Is that not the case? Note: I'm not a 1Password customer.

Maybe technical customers who knew it were Electron. I knew, and don't really care. My wife doesn't even know what Electron is- everything is just another app to her.

Re: Tailscale raises $100M

#205
post #159

Earlier quoted context omitted.

For me, it was their switch to an Electron app. "High security" and "built from dozens of third party libraries and running on a browser" don't belong together.

The choice of tech stack for a desktop application seems like an interesting basis to claim a company has lost touch with its core values.

I’m fully in the camp who believes critical, top-level security should not co-exist with npm pulling dozens of 3rd party libraries which each pull even more 4th party code.

Is there anyone here with a counter argument? Has a security review been performed on each dependency? Any reason to think my fear is unfounded?

Re: Tailscale raises $100M

#206

Earlier quoted context omitted.

There's a kind of WIP control server implementation, it's not production ready in my opinion but it's definitely usable. https://github.com/juanfont/headscale

Super cool, and a lot of contributors! Can this work the rest of the wireguard ecosystem (agents, UIs, ...) for a full VPN soln without involving the VC-tied company?

Yes it works with all of the Tailscale clients except for iOS. No it does not work with clients from the broader Wireguard ecosystem (e.g the Wireguard iOS app).

Re: Tailscale raises $100M

#207
post #181

Earlier quoted context omitted.

Does Nebula have anything like Tailscale's rules engine? I am absolutely in love with being able to configure all my connections by just specifying a JSON file somewhere. No need to have firewalls, the configuration specifies which service or user can talk to which. That having been said, I also am wary of using Tailscale for the same reasons as above, I have to trust Tailscale and Github? I can maybe justify trustin…

It does! In fact replacing AWS security groups and making them cross region and cross platform was probably the first goal of the project. My coauthor, Nate, wrote Nebula's internal firewall code before we wrote a single line of the actual protocol, because he wanted to ensure it was performant enough for massive scale.

Well that is great, thank you! I will play with it today.

Re: Tailscale raises $100M

#208
post #167

Earlier quoted context omitted.

Indeed, this is why I won't use it either. I settled on Slack's Nebula [0] instead of wireguard because it handles direct p2p communication between nodes automatically. There also exists an open source implementation of the tailscale control server [1] that you could self host. [0] https://github.com/slackhq/nebula [1] https://github.com/juanfont/headscale

(Nebula coauthor here) People sometimes ask me to describe the differences between Nebula and Tailscale. One of the most important relates to performance and scale. Nebula can handle the amount of internal network traffic and scalability of nodes (100k+ nodes, constant churn) required on a large network like Slack's, but Tailscale cannot. Tailscale's performance is fine for many situations, but not suitable for infra…

Tailscalar here. Tailscale can handle 100k+ nodes with lots of churn just fine.

Re: Tailscale raises $100M

#209
post #203

Earlier quoted context omitted.

... if your definition of "home routers" excludes ISP-provided ones, then I'll agree. Unfortunately, I'm pretty sure that either you are on an ISP that actually cared and found a good supplier or didn't check out what are the capabilities of ISP-provided routers.

Of the three ISPs in my area that I have used, all of them allowed inbound traffic and either had useful controls in their routers or didn't supply a router, just an ethernet handoff. RCN, Comcast, Verizon. All of them filtered out the SMB/CIFS ports. Two of them filtered outbound port 25; one of them was willing to open it with the additional cost of a static IP.

Yeah, it's inconsistent to be honest. I've found that Hitron to not have any sort of firewalls (except for IPv4 NAT if you consider it as a firewall), while Huawei routers (which is not used in the US for reasons hopefully known to you) do have an IPv6 firewall that is only an off or on switch, stupidly their enterprise stuff do have advanced controls, Alcatel/Nokia-branded ones are inconsistent to say the least and the same can be said for Zyxel. I'm actually interested in checking out other routers used by ISPs, but those are the ones I've actually seen.

Re: Tailscale raises $100M

#210
post #39

Earlier quoted context omitted.

Tailscale is one of the ways you can restore the end-to-end connectivity principle that IP introduced and that NAT destroyed.

This is kind of overstated. Even if everyone went IPv6 and gave every device a public IP address, pretty much every network would have a firewall that behaved just like NAT.

Our epic treatise on how NAT traversal works (in general, not specific to Tailscale) mentions this. IPv6 greatly reduces the amount of pain for p2p connections, but does not eliminate some of the fundamentals (stateful firewall traversal) if you want it to be zero-config: https://tailscale.com/blog/how-nat-traversal-works/

But until deployment hits 100%, and until ISPs start caring about IPv6 reliability the way they do about IPv4, "just use IPv6" can't be your answer. It's lovely when it works, but you need to do something other than "give up" when it doesn't. (also, as long as the internet is dual-stacked, doing IPv6 right also implies figuring out if NAT64 is in play, and wielding it correctly; so arguably IPv6 adds more complexity to the overall story, for now :) )

Post reply on HN