Live data from Hacker News

Tailnet Lock

tailscale.com

31–40 of 119 posts

Re: Tailnet Lock

#33

> ...by architecting our infrastructure with security and privacy in mind. The blog and the website loads in so many trackers (reasonable, given metrics are important when you're busy hyperscaling a venture-backed startup), that folks at Tailscale should seriously reconsider positioning themselves as some paragons of privacy. No offence (:

> website loads in so many trackers

Not on my browser. Maybe you should consider a better browser and/or install some extensions.

Re: Tailnet Lock

#34
For basic tunneling into home servers, is Tailnet.. overkill? Ie i could expose my IP via Dyn DNS, or i could use something like Cloudflare or Tailnet to tunnel into the network. However.. i'm not sure what the right fit is. Would you recommend Tailnet for someone who just wants to expose some internal IPs to the public in a safe way?

Tunneling compared to Dyn DNS at least has the advantage of more security via reduced access to ports. So maybe that alone is worth $5/m. .. well, $10/m, since i have two users. $10/m seems a bit steep just for some small access to my internal network for things like Camera Feeds, etc.

Dyn DNS + some safe self hosted VPN might be more affordable and just as safe compared to Tailscale.

.. thoughts on the best service to price ratio for my needs?

Re: Tailnet Lock

#35
post #12

Why is there a post by tailscale on the front page every single day?

As a (typical?) HNer, there are many reasons. (a) TailScale was founded and is populated by people I followed online before, during, and after my and their tenures at Google, or just followed online already if they're not Xooglers (b) their product is extremely useful, and almost every non-enterprisey new feature they add is immediately or potentially useful to me, and I'm only running a couple of Raspberry Pis and a Minecraft server (c) I like Go, and they use Go extensively, often improving Go in the process, or at least documenting interesting performance characteristics and application design architectures (d) they have managed to find an interesting and rare balance point, to applying commercially viable product funding to a whole host of open source improvements and contributions, and (e) the basic components of their product (Wireguard, networking details, Kernel integration, etc.) are extremely in my areas of interest even independent of the product itself.

Also, they're just awesome folks!

Re: Tailnet Lock

#36
post #9

I am one of those users who have asked, but how can I trust that the Tailscale coordination server will not inject hidden public keys to my network. This feature is a very good step forward in security. I will take a look and if the implementation is sound, I am going to use Tailscale (namely if the Tailscale is compromised, I will not be automatically compromised, unless I manually accept external public keys, or in…

If you don't want to trust the Tailscale coordination server, and decide that tailnet lock is not for you, have you taken a look at Headscale? https://github.com/juanfont/headscale

Re: Tailnet Lock

#37
post #26

Earlier quoted context omitted.

How can I trust that I can log in and administer my network when Google kills my Google Account login or Microsoft kills my GitHub Account? Big tech surveillance orgs being the SSO is an SPoF for the administration of the network. For something as critical as L3, I can't accept that. I just use Nebula instead. It doesn't have a spiffy web interface or ssh auth chrome bolted on, but it works great for my purposes and…

Tailscalar here. IdP trust is on the list. There are some "easy" things we can do that help on the surface but make life harder for users. And there are some not-so-easy things we are researching. I hope to have answers in 2023.

I recently read this blog [0] about how tailscale was thinking of open sourcing a small coordination server but headscale had already been created so that effort was put on hold.

Is tailscale at this point in any way involved in headscale or contributing to it or are there plans to fork it to keep it maintained?

Asking out of curiosity.

[0]: https://tailscale.com/blog/opensource/

Re: Tailnet Lock

#39
I found the blog post slightly confusing because it never explicitly spells out that endorsing a new node is a manual operation that the administrator has to perform from one of the trusted nodes. Of course this is what you'd want, anything automatic would ruin the purpose of tailnet lock. But still not seeing it mentioned, neither in the text nor in the pictures, made me wonder what I had missed, until I watched the video which features that very step as part of the demo.

Re: Tailnet Lock

#40
post #12

Why is there a post by tailscale on the front page every single day?

Because someone submits them, and others upvote them. It's really not complicated. There's no deep conspiracy to promote Tailscale here. They're not even a YC company.
Post reply on HN