Earlier quoted context omitted.
Pretty much this. DNS, SNI, and otherwise plaintext traffic sniffing. That together with user/device 'fingerprinting' (a much more amorphous concept), and that's why such-and-such thing you were just talking about with so-and-so pops up on your screen/feed/whatever, sometimes only minutes later. I highly doubt any of this can actually be opted-out of. How else would they stay in business?
They specifically avoid sending traffic through tailscale servers whenever possible. That’s how the free tier stays free. Most connections are direct, P2P. The traffic that does go through their servers is encrypted, and bandwidth limited on the free plan. Any snooping on client behavior would have to be done client side, and the clients are all open source. To some extent the coordination server might be able to ded…
Tailscale Peer Relays is now generally available
221–230 of 267 posts
Re: Tailscale Peer Relays is now generally available
#222Earlier quoted context omitted.
just stop paying them, as though migrating to an alternative is free and easy
In this case it really is easy. It's just wireguard with some NAT negotiation sauce and convenient auth layer.
The integrated service is very valuable and obviously genuinely popular.
Re: Tailscale Peer Relays is now generally available
#223Earlier quoted context omitted.
I also have to eat and put a roof over my head. Tying that to a system that can change permanently at any time to something less helpful is dangerous. Preferring open source is a risk mitigation strategy. The closed alternative may have better features to make them worth that risk though.
One feature is: it's a business and won't be abandoned due to OSS but out if it has a sustainable way to continue.
The amount of businesses closed, sold and products abandoned or swapped for the more controlled/exploitable ones is numerous, on the other hand.
Re: Tailscale Peer Relays is now generally available
#224Re: Tailscale Peer Relays is now generally available
#225It's a bit disingenuous to present solutions like Tailscale as more secure than opening a VPN port on one's on machine. The latter solution should always be preferred when available just because you don't want your infrastructure to depend on a "free" service which might cease to be free tomorrow.
Things are much more unscrupulous than potentially ceasing to be free tomorrow. Nobody who values their privacy would ever route their network traffic through a 'free' service.
Tailsacle provides managed, policy-driven secure connectivity, where the network admin controls access, and where packet payloads are end-to-end encrypted between their nodes using device-to-device links that are WireGuard-based. Their TCP relay system (DERP) helps connectivity when direct peer-to-peer isn’t possible, but traffic through DERP still remains end-to-end encrypted.
Re: Tailscale Peer Relays is now generally available
#226Re: Tailscale Peer Relays is now generally available
#227Earlier quoted context omitted.
But you clearly see value in the restaurant experience, even with the shortcoming of a line. Or else you wouldn’t go.
You’re missing the point. The restaurant experience would be better without a line. I tolerate lines if the restaurant experience is good enough. If it is not, I go somewhere else. “Going somewhere else” is not always an option when it comes to computers/software.
Re: Tailscale Peer Relays is now generally available
#228Re: Tailscale Peer Relays is now generally available
#229Earlier quoted context omitted.
The logic of putting roof over the head is a point that is too broadly used is not at all valid for things like tailscale as... eventually most businesses at that level (tailscale revenue in 2025 was $45.2M) are crushing the customers. Either entshittification or lock-in. There is a loss of trust. The trust on SV/software is as much as bankers (during Lehmann bros crisis). Some people in HN think oh, we are growing s…
So, the people building yachts also need to pay the bills. Or should the world not have yachts?
Maybe? Things like super yachts are just offensive.
Re: Tailscale Peer Relays is now generally available
#230If you're sold on Tailscale due to them "being open" (as they semi-officially support the development of Headscale), keep in mind, that at the same time some of their clients are closed source and proprietary, and thus totally controlled by them and the official distribution channels, like Apple. Some of the arguments given for this stance are just ridiculous: > If users are comfortable running non-open operating sys…
(Tailscalar here) To be clear: it's only the GUIs that are closed source on selected platforms.