Live data from Hacker News

Tailscale raises $100M

tailscale.com

281–290 of 468 posts

Re: Tailscale raises $100M

#281
post #224

Earlier quoted context omitted.

> a direct ring of trust with friends The vision you outlined is great, except it doesn't work. The trust assumptions are too high, and even a great product like Tailscale seems to rely completely on centralized identity providers (you have to choose Google, Microsoft, or Github on sign-in). Ultimately, if you want to maintain full control of your online identity and network, you'll probably need some of the decentra…

I self host headscale as my control node of my tailscale vpn so no sign ins required, I just give keys out to anyone I want in my vpn. My problem is the client doesn't support multiple servers, so I can't have a work vpn and a home vpn, not even with an easy toggle - you have to run tailscale with different conf options for both. Changing namespaces also isn't easy, so having friends and family segregated even on one…

Thanks the main objection I have with tailscale is that you can't self-host (and you need external identity providers). I had no idea there was a self host option. I'll investigate. I assume it's an unsupported community option?

Re: Tailscale raises $100M

#282

Tailscale has a fantastic product, I’ve been extremely happy from day one. If you’re waiting for a weekend to have a few hours to try out Tailscale, don’t, it takes 15 minutes to get every device you own up and running and talking. This is the lowest friction personal VPN to ever exist, and once you see how easy it is for your own devices, you’ll wish you had it at work. The biggest risk that this company has is that…

I’m pretty ignorant on this topic, but what are the benefits of having a personal VPN?

For me: direct routing between endpoints, thus reducing the lag and spec restrictions you get from routing through a single VPN server.

Other things are seamless transition to local networks, and you can even have local network encryption.

Re: Tailscale raises $100M

#283
post #167

Earlier quoted context omitted.

Indeed, this is why I won't use it either. I settled on Slack's Nebula [0] instead of wireguard because it handles direct p2p communication between nodes automatically. There also exists an open source implementation of the tailscale control server [1] that you could self host. [0] https://github.com/slackhq/nebula [1] https://github.com/juanfont/headscale

(Nebula coauthor here) People sometimes ask me to describe the differences between Nebula and Tailscale. One of the most important relates to performance and scale. Nebula can handle the amount of internal network traffic and scalability of nodes (100k+ nodes, constant churn) required on a large network like Slack's, but Tailscale cannot. Tailscale's performance is fine for many situations, but not suitable for infra…

Nebula rocks!

Re: Tailscale raises $100M

#285

Earlier quoted context omitted.

Indeed, this is why I won't use it either. I settled on Slack's Nebula [0] instead of wireguard because it handles direct p2p communication between nodes automatically. There also exists an open source implementation of the tailscale control server [1] that you could self host. [0] https://github.com/slackhq/nebula [1] https://github.com/juanfont/headscale

Absolutely love nebula and really wanted it to win when I did my overlay network shootout (for personal use). But device on-boarding and management was overly complex for a lay person (I have a couple users that would require access). I settled on ZeroTier for now. Unfortunately, I don't think ZeroTier is my long term solution. Their self-hosted option comes with a plethora of caveats that make it basically unusable.…

I am curious what you found complex - was it the PKI? I was able to get Nebula up and running WAY faster than any of the others. It's two (well really only one) binaries and a config file - the simplicity is awesome.

Re: Tailscale raises $100M

#286
post #137

Earlier quoted context omitted.

I’m pretty ignorant on this topic, but what are the benefits of having a personal VPN?

I am able to route traffic on my mobile device through my home network via the use of their "exit node" option. It allows one of my home devices to act as an exit node for my entire personal tailscale network. This serves multiple benefits: the main one being that I receive pi-hole filtered ad-free traffic on my mobile device via a Wireguard VPN with my home IP 24/7/365

What other benefits are there? I use a PiHole to block ads on my phone already, but I do it via a PiHole installed on an EC2 instance that I also use as an IRC bouncer and other things.

Re: Tailscale raises $100M

#287
post #263

Earlier quoted context omitted.

Which also applies to Tailscale's SD-WAN and cloud VPN competitors.

But doesn't apply to my wireguard setup on my OPNSense installation at home.

This is the HN disconnect: people commenting here have completely different concerns than Tailscale's actual customers.

Re: Tailscale raises $100M

#288
post #244
post #173

Earlier quoted context omitted.

This is how people fix things caused by commercial entities being abusive. It's done quite a bit, most of the critical things people rely on are regulated. Do you live in a place that doesn't regulate things?

You could spend time to learn about the process, deal with months or years of lobbying, deal with counter-lobbying, and eventually win your position or maybe not. Or you could use this technical workaround. And maybe we're all worse-off for it, but now you're done dealing with that issue.

Yes, so I think it is reasonable that someone who stumbles upon $100,000,000 and wants to "fix the Internet" aim a little higher than making it as easy as possible to do the technical workarounds that leave us all worse-off.

Re: Tailscale raises $100M

#289
post #181

Earlier quoted context omitted.

It does! In fact replacing AWS security groups and making them cross region and cross platform was probably the first goal of the project. My coauthor, Nate, wrote Nebula's internal firewall code before we wrote a single line of the actual protocol, because he wanted to ensure it was performant enough for massive scale.

Well that is great, thank you! I will play with it today.

Ah, it looks like the firewall rules need to be copied to each host separately. That's not a dealbreaker, but not as easy to deploy as having them managed centrally (by the lighthouse, I guess?).

Re: Tailscale raises $100M

#290
post #49

Earlier quoted context omitted.

Indeed, 1Password is practically a utility at this point, as far as I'm concerned. I really like the direction they're heading and they're solving some pretty tricky problems without compromising on security, predominantly in the enterprise domain. The experience is the same regardless of whether you're an enterprise user or a personal or family user. It's polished enough that my grandma can use it.

> I really like the direction [1Password] is heading I thought customers were complainingly loudly against their new direction of making 1Password an Electron app. Is that not the case? Note: I'm not a 1Password customer.

> I thought customers were complainingly loudly against ...

No, you confuse "customers" with a vocal minority.

Post reply on HN