Live data from Hacker News

Tailscale raises $100M

tailscale.com

211–220 of 468 posts

Re: Tailscale raises $100M

#211
post #9

With such a huge investment comes the obligation to eventually pay it back. Is this another one of my favourite tools going the way of Dropbox, 1Password and all other companies that were formed around what should be a platform feature, which took on way too large investment sums and were eventually forced to become the everything, losing sight of their core values? I sincerely hope not, but there's so much bad prece…

Dropbox has been fine ish? Like not stellar but it’s still something I use as one of my core tools and pay for.

Ditto, but the fact that they still can’t handle more than ~300k files is a long-standing problem they have yet to solve. I have close to a million syncing files and startup time for the app takes about 20 minutes on a brand new MBP, and CPU and overall energy usage is ridiculously high. All while they keep pushing me to backup more files.

I pay over $700/ yr for their business plan and would like to have better performance for it.

Re: Tailscale raises $100M

#212
post #38
post #10

> For people who believe there’s a catch — and most still do — then I don’t know how to write a blog post or hire a marketing or sales team to change their minds. I think the catch is that (at least at the free level) one must trust an identity providers. For many companies that's probably fair enough, but for high-security companies and private individuals one absolutely cannot trust anything running outside of one'…

Tailscale will let you use any SAML or OIDC provider you like in the Enterprise plan (presumably because of the cost of supporting the long tail of nonsense IdPs will produce). (Disclosure: I'm a (small) investor via Latacora's sibling fund, Lagomorphic.)

That only addresses half the problem, though, right? Can't Tailscale still add any nodes they want to one's network?

Also, it doesn't address the individual case, but that's fair enough: Tailscale isn't a charity.

Re: Tailscale raises $100M

#213
Things I’m really looking forward to seeing from Tailscale / projects I’d like to tinker with:

- Better iOS battery life, there have been many improvements but it’s still too much to leave running 24/7, I understand they’re making improvements here

- Their in built SSH server which seems to be in development

- Using Tailscale ACLs to control access to Kubernetes ingress resources, they recently released an nginx auth plugin so I imagine this is now possible if you attach a Tailscale sidecar to the nginx ingress controller

- Arbitrary ACLs which also seem to be in progress, it would be awesome to define in ACLs who has access to different parts of e.g a backoffice application

- Official support for DNS extra records, already using this with the Headscale self hosted control plane for personal projects but it would be great to use it on Tailscale too

- Kernel Wireguard for the data plane, I think this is on the roadmap?

Overall a fantastic piece of software which I use for both personal and professional projects.

Re: Tailscale raises $100M

#214
Excuse my ignorance but this is something I have been longing to ask for. Do these services compromise security? Wouldn't you put too much trust on these services, like 1Password. If that service is compromised in someway aren't you exposed? Is these a good article debate on this topic. Thanks.

Re: Tailscale raises $100M

#215
post #81

Earlier quoted context omitted.

I thought that Tailscale was pretty interesting. Avery Pennarun, its CTO, is somebody whose judgment I am used to trusting. Then I learned that to use it, I would be dependent on authenticating using a login on one of the unaccountable internet behemoths who could take away my account for any random reason or no expressed reason at all. No, thank you.

Google does that, Microsoft doesn't. Microsoft will ban you from a particular service if you egregiously violate the terms of service for a particular application of theirs, but never the whole account. Google will throw you on your ass in the blink of an eye.

Is there anything in there TOS that states it or has this just been their practice so far?

Re: Tailscale raises $100M

#216
post #167

Earlier quoted context omitted.

(Nebula coauthor here) People sometimes ask me to describe the differences between Nebula and Tailscale. One of the most important relates to performance and scale. Nebula can handle the amount of internal network traffic and scalability of nodes (100k+ nodes, constant churn) required on a large network like Slack's, but Tailscale cannot. Tailscale's performance is fine for many situations, but not suitable for infra…

Tailscalar here. Tailscale can handle 100k+ nodes with lots of churn just fine.

Fair enough. I am sure the key distribution is fast and all that, but not needing peer key distribution at all was a goal and the overhead associated is less scalable than just not doing it at all. Regardless, very cool that you can handle that many nodes, which is a hard problem. I assume you do just-in-time key distribution or something, because (n-1) distribution of peer keys would be ... less than ideal.

Anywho, the more important bit is my point about performance. Nebula is significantly faster than userspace Wireguard, and plain userspace Wireguard is (last I checked) a bit faster than Tailscale, due to the additional code needed for things like your ACLs. At gigabit type scale it is probably fine and not noticeable, but at Slack, we needed to scale to 10G+ on links, while ensuring we didn't take a significant hit on CPU resources.

Again, I think Tailscale is very good for its target use case as a VPN replacement, and congrats on raising these funds!

Re: Tailscale raises $100M

#218
I love tailscale.

Lately I have been migrating all my self-hosted stuff into a raspberry pi (instead of running a public instance in the cloud). It gives me a bit of piece of mind knowing that it adds an extra layer of security (to hit any of my endpoints/apps you would need to infiltrate my VPN). And it will save me a lot of money on hosting.

I don't need to expose my computers publicly or enable upnp or anything. It just works.

Re: Tailscale raises $100M

#219
post #9

With such a huge investment comes the obligation to eventually pay it back. Is this another one of my favourite tools going the way of Dropbox, 1Password and all other companies that were formed around what should be a platform feature, which took on way too large investment sums and were eventually forced to become the everything, losing sight of their core values? I sincerely hope not, but there's so much bad prece…

I haven't really felt like 1Password's product materially strayed from the original mission. If anything, I'm even more delighted with the team functionality, shared vaults, quick keyboard access in 1Password 8, etc. I wouldn't put them in the Dropbox bucket. Also, I think the value Tailscale provides is fairly unique and far from obviously a platform feature like file storage and perhaps even password management.

I think they changed from their mission to make password management easy and secure to extracting service fees forever.

I don’t necessarily blame them but think their decision was pushed along by the need for big money.

For example, I think they’d still be able to do the pay once model if they abstracted they storage to work with Dropbox/icloud/OneDrive/whatever.

There’s really no value add as a user for a monthly fee. Although lots of people don’t mind. I’d rather not pay for something as essential and simple as a synchronized, encrypted data blob. I literally replaced it with a Google doc and cutting and pasting more. A filter over Google docs does not require a monthly fee.

I have this problem with lots of SaaS products that could be software if they didn’t want or need lots of money.

Re: Tailscale raises $100M

#220

Earlier quoted context omitted.

> a direct ring of trust with friends The vision you outlined is great, except it doesn't work. The trust assumptions are too high, and even a great product like Tailscale seems to rely completely on centralized identity providers (you have to choose Google, Microsoft, or Github on sign-in). Ultimately, if you want to maintain full control of your online identity and network, you'll probably need some of the decentra…

I feel like people are so concerned about infinite scaling that nobody ever tries to scale to 5 anymore. I have a big collection of movies, and I’d like my mom-technical blue collar friends to be able to watch them. I trust them, and I have trusted communication channels with them. We exchange keys somehow . With the sort of routing I’m describing, they could watch my movies and I wouldn’t have to have a public IP ad…

> And I wouldn’t mind if their friends (that aren’t my friends) watch my movies, either, by forwarding through my friends.

This is the part that doesn't scale. Hell, this is extremely risky even at a small scale. You don't know who your friends' friends are, you will have friends that abuse this, and you will end up with a much larger network than you anticipated.

How many of your friends and family are "friends" with bots on Facebook?

Post reply on HN