Live data from Hacker News

Netbird – Open Source Zero Trust Networking

netbird.io

281–290 of 299 posts

Re: Netbird – Open Source Zero Trust Networking

#282

Earlier quoted context omitted.

Could you give a brief description of your use case? I'm looking at all the tailscale buzzwords on their site, but am not really understanding what I would use this for in my home setup

I have one VPS node that I use as a connector, where the headscale app is installed. I have this on a domain (for convenience), so think something like: hs.mygreatplace.com Now, when I install Tailscale client on any device (phones, tablets, Linux machines, proxmox nodes, etc.), I simply say: don't use the tailscale network for this, please route this over my own network, so you point it to hs.mygreatplace.com as a c…

Tailscale is based in Toronto I believe.

Re: Netbird – Open Source Zero Trust Networking

#283

Earlier quoted context omitted.

I guess I'll just say that I hope you share the blame with the appropriate parties whenever you are suffering through iOS entitlements and provisioning to publish or self-load it on your iPhone, since Netbird's iOS client is open source. Though, maybe it's not doing business in the US, and maybe the app is not similarly geo-blocked. Actually can you not just pull the app and then side-load it anyway? That's what I wo…

I'm not sure where you saw ire. The only direct negativity was aimed at restrictions themselves, which is the product of foreign policy of specific countries and Apple politics. I'm not angry at Tailscale, just disappointed and annoyed. > Actually can you not just pull the app and then side-load it anyway? That's what I would do if I couldn't get Tailscale from the Play Store... The issue is, even if it's possible (w…

[deleted]

Re: Netbird – Open Source Zero Trust Networking

#284

Earlier quoted context omitted.

I guess I'll just say that I hope you share the blame with the appropriate parties whenever you are suffering through iOS entitlements and provisioning to publish or self-load it on your iPhone, since Netbird's iOS client is open source. Though, maybe it's not doing business in the US, and maybe the app is not similarly geo-blocked. Actually can you not just pull the app and then side-load it anyway? That's what I wo…

I'm not sure where you saw ire. The only direct negativity was aimed at restrictions themselves, which is the product of foreign policy of specific countries and Apple politics. I'm not angry at Tailscale, just disappointed and annoyed. > Actually can you not just pull the app and then side-load it anyway? That's what I would do if I couldn't get Tailscale from the Play Store... The issue is, even if it's possible (w…

It's interesting how you seem to dance around understanding exactly why Tailscale is geo-blocked and then also try to act "curious" like Netbird will be different. And somehow, you can't or won't just go check for yourself if the app is available in your region. Hm.

Re: Netbird – Open Source Zero Trust Networking

#287

How does this compare with Defguard? Also European but seems more featureful maybe?

Hi, Robert from Defguard here.

Defguard is a *Secure by Design* solution, which means security is important (if not more) then functionality. Lower latency or peer-to-peer communication does not automatically mean better security often it means a larger attack surface.

Defguard is also *the only solution that enforces MFA on every connection*, aligning with true Zero Trust principles never trust a user or device by default.

Why Peer-to-Peer Is Not Safer?

Peer-to-peer and mesh solutions can be faster because traffic flows directly between peers, but they almost always expose all components publicly and make it easier to hijack the network or inject unauthorized peers.

So what does Defguard’s Secure-by-Design Architecture mean?

1. Minimal gateway exposure

The Defguard gateway exposes only a WireGuard port. Compromising it would require a Linux kernel or WireGuard zero-day at that point, no solution is safe.

2. Isolated, stateless proxy

The only Internet-facing "application" component is a stateless proxy, deployed in a separate network segment. It has no access to the gateway, core, or internal resources.

3. Protected control plane

The core (control plane) runs strictly inside the intranet (local network that should not be exposed anywhere). No user data are exposed to the Internet or DMZ/other network segments. Also the MFA validation process is done in secure network segments (for example when doing MFA with Desktop + Mobile client biometry/faceID combined).

Why This Is Different from Mesh Solutions?

Most mesh VPN solutions expose their control and peer-discovery components publicly by design. This significantly increases the risk of compromise and peer injection.

So that's about it.

Re: Netbird – Open Source Zero Trust Networking

#290

Earlier quoted context omitted.

I'm not sure where you saw ire. The only direct negativity was aimed at restrictions themselves, which is the product of foreign policy of specific countries and Apple politics. I'm not angry at Tailscale, just disappointed and annoyed. > Actually can you not just pull the app and then side-load it anyway? That's what I would do if I couldn't get Tailscale from the Play Store... The issue is, even if it's possible (w…

It's interesting how you seem to dance around understanding exactly why Tailscale is geo-blocked and then also try to act "curious" like Netbird will be different. And somehow, you can't or won't just go check for yourself if the app is available in your region. Hm.

And it's interesting how you miss that it's not me I was talking of, assume I own an iOS device to check anything and am in the same region where the Tailscale client is geoblocked. Not to mention how you mixed Google Play and Apple App store during the discussion. Hm.
Post reply on HN