Netbird – Open Source Zero Trust Networking
281–290 of 299 posts
Re: Netbird – Open Source Zero Trust Networking
#282Earlier quoted context omitted.
Could you give a brief description of your use case? I'm looking at all the tailscale buzzwords on their site, but am not really understanding what I would use this for in my home setup
I have one VPS node that I use as a connector, where the headscale app is installed. I have this on a domain (for convenience), so think something like: hs.mygreatplace.com Now, when I install Tailscale client on any device (phones, tablets, Linux machines, proxmox nodes, etc.), I simply say: don't use the tailscale network for this, please route this over my own network, so you point it to hs.mygreatplace.com as a c…
Re: Netbird – Open Source Zero Trust Networking
#283Earlier quoted context omitted.
I guess I'll just say that I hope you share the blame with the appropriate parties whenever you are suffering through iOS entitlements and provisioning to publish or self-load it on your iPhone, since Netbird's iOS client is open source. Though, maybe it's not doing business in the US, and maybe the app is not similarly geo-blocked. Actually can you not just pull the app and then side-load it anyway? That's what I wo…
I'm not sure where you saw ire. The only direct negativity was aimed at restrictions themselves, which is the product of foreign policy of specific countries and Apple politics. I'm not angry at Tailscale, just disappointed and annoyed. > Actually can you not just pull the app and then side-load it anyway? That's what I would do if I couldn't get Tailscale from the Play Store... The issue is, even if it's possible (w…
Re: Netbird – Open Source Zero Trust Networking
#284Earlier quoted context omitted.
I guess I'll just say that I hope you share the blame with the appropriate parties whenever you are suffering through iOS entitlements and provisioning to publish or self-load it on your iPhone, since Netbird's iOS client is open source. Though, maybe it's not doing business in the US, and maybe the app is not similarly geo-blocked. Actually can you not just pull the app and then side-load it anyway? That's what I wo…
I'm not sure where you saw ire. The only direct negativity was aimed at restrictions themselves, which is the product of foreign policy of specific countries and Apple politics. I'm not angry at Tailscale, just disappointed and annoyed. > Actually can you not just pull the app and then side-load it anyway? That's what I would do if I couldn't get Tailscale from the Play Store... The issue is, even if it's possible (w…
Re: Netbird – Open Source Zero Trust Networking
#285Re: Netbird – Open Source Zero Trust Networking
#286Re: Netbird – Open Source Zero Trust Networking
#287How does this compare with Defguard? Also European but seems more featureful maybe?
Defguard is a *Secure by Design* solution, which means security is important (if not more) then functionality. Lower latency or peer-to-peer communication does not automatically mean better security often it means a larger attack surface.
Defguard is also *the only solution that enforces MFA on every connection*, aligning with true Zero Trust principles never trust a user or device by default.
Why Peer-to-Peer Is Not Safer?
Peer-to-peer and mesh solutions can be faster because traffic flows directly between peers, but they almost always expose all components publicly and make it easier to hijack the network or inject unauthorized peers.
So what does Defguard’s Secure-by-Design Architecture mean?
1. Minimal gateway exposure
The Defguard gateway exposes only a WireGuard port. Compromising it would require a Linux kernel or WireGuard zero-day at that point, no solution is safe.
2. Isolated, stateless proxy
The only Internet-facing "application" component is a stateless proxy, deployed in a separate network segment. It has no access to the gateway, core, or internal resources.
3. Protected control plane
The core (control plane) runs strictly inside the intranet (local network that should not be exposed anywhere). No user data are exposed to the Internet or DMZ/other network segments. Also the MFA validation process is done in secure network segments (for example when doing MFA with Desktop + Mobile client biometry/faceID combined).
Why This Is Different from Mesh Solutions?
Most mesh VPN solutions expose their control and peer-discovery components publicly by design. This significantly increases the risk of compromise and peer injection.
So that's about it.
Re: Netbird – Open Source Zero Trust Networking
#288Re: Netbird – Open Source Zero Trust Networking
#289Re: Netbird – Open Source Zero Trust Networking
#290Earlier quoted context omitted.
I'm not sure where you saw ire. The only direct negativity was aimed at restrictions themselves, which is the product of foreign policy of specific countries and Apple politics. I'm not angry at Tailscale, just disappointed and annoyed. > Actually can you not just pull the app and then side-load it anyway? That's what I would do if I couldn't get Tailscale from the Play Store... The issue is, even if it's possible (w…
It's interesting how you seem to dance around understanding exactly why Tailscale is geo-blocked and then also try to act "curious" like Netbird will be different. And somehow, you can't or won't just go check for yourself if the app is available in your region. Hm.