Live data from Hacker News

Tailscale has raised $160M

tailscale.com

321–330 of 354 posts

Re: Tailscale has raised $160M

#321

Earlier quoted context omitted.

That seems like even more reason to use an overlay - it abstracts all that instability away and gives you a consistent, secure network regardless of what the underlying IPs are doing. Obviously peers can have static IPs too if you think that makes them more stable to routing changes (it doesn't).

Do you really think that a tailscale VPN is necessary to deal with link failures? It is not BGP and SD-WAN or MPLS l2 VPN can do that.

I didn't mention Tailscale. I said "overlay", and both SD-WAN and MPLS L2 VPN are overlay networks.

Re: Tailscale has raised $160M

#322

Earlier quoted context omitted.

Sure, but your data is only getting relayed through DERP servers if it cant otherwise establish a direct p2p connection. This can usually be resolved at either side of the connection - if you know about it (which is what the parent was suggesting could be made more clear). As for your bandwidth concerns in the case of needing to relay, you can even set up your own relay ( https://tailscale.com/kb/1118/custom-derp-ser…

I never said I had a desire to be more centralised. I just said that static IPs and open ports remove the necessity for hole punching/STUN. You can have multiple sites without a central and all use static IPs and open ports.

I was replying to your comment about you wanting to control QoS for relaying.

Re: Tailscale has raised $160M

#323

Earlier quoted context omitted.

You're not wrong to think Tailscale is primarily a software company, and yes, salaries are a big part of any software company's costs. But it's definitely more complex than just payroll. A few other things: 1. Go-to-market costs Even with Tailscale's amazing product-led growth, you eventually hit a ceiling. Scaling into enterprise means real sales and marketing spend—think field sales, events, paid acquisition, conte…

> but it may mean building new standards on top of the duct-taped 1980s-era networking stack the modern Internet still runs on. That’s a path directly into a money burning machine that goes nowhere. This has been tried so many times by far larger companies, academics, and research labs but it never works (see all proposals for things like content address networking, etc). You either get zero adoption or you just run…

Totally fair to bring up IPv6 vs. IPv4. However, I think Tailscale’s approach might sidestep some of that pain.

Avery (Tailscale CEO) has actually written about IPv6 in the past:

    - https://apenwarr.ca/log/20170810 (2017)
    - https://tailscale.com/blog/two-internets-both-flakey (2020)
IPv6 has struggled in adoption not because it’s bad, but because it requires a full-stack cutover, from edge devices all the way to ISP infra. That’s a non-starter unless you’re doing greenfield deployments.

Tailscale, on the other hand, doesn’t need to wait for the Internet to upgrade. Their model sits on top of the existing stack, works through NATs, and focuses on "identity-first networking". They could evolve at the transport or app layer rather than rip and replacing at the network layer. That gives them way more flexibility to innovate without requiring global consensus.

Again, I don’t know what their specific plans are, but if they’re chasing something at that layer, it’s not crazy to think of it more like building a new abstraction on top of TCP/IP vs. trying to replace it.

Re: Tailscale has raised $160M

#324

I'm a fan of TS and have been a paying customer for work infra for almost a year now. It really is well put together and easy to use, but I do run up against some issues/complaints when diving deep that I hope they can work out: * The pricing tiers and included features by tier penalizes you in frustrating ways. The base plan is a reasonable $6/user/m, but if you want to use ACLs to control anything in a workable way…

> * Better tooling to determine why it's falling back to DERP instead of direct for remote clients. DERP relays should be an absolute last resort to provide connectivity for Business-plan-level customers (very slow), and the way TS works just assumes any connectivity is fine. Tailscale touts all the perf benefits of the wireguard protocol but in practice between the userland wireguard that seems to be used all the ti…

I thought they vastly improved user-space wireguard performance?

https://tailscale.com/blog/more-throughput

Not sure if the kernel implementation pulled ahead again, I don't really follow these things.

Also not defending tailscale, I respect them but I agree they are a one size fits some solution.

Re: Tailscale has raised $160M

#325
post #316

Earlier quoted context omitted.

What are you on about. For years logging in with email was possible even on the most amateurish projects. Now that's not possible for tailscale? Why

Because they don't want your password and as a security company, I applaud that. Account issues, recovery, support that can be manipulated, a single breach or bad password that grants access to their admin interfaces, implementing their own 2FA. And, serious people want SSO anyway, and most people have some kind of authentication they can lean on. You can make a stodgy password login if you want, or you can run a key…

Microsoft was hacked before and I don't trust them but I trust the email provider at the company I work for now what

Re: Tailscale has raised $160M

#326

Earlier quoted context omitted.

Do you really think that a tailscale VPN is necessary to deal with link failures? It is not BGP and SD-WAN or MPLS l2 VPN can do that.

I didn't mention Tailscale. I said "overlay", and both SD-WAN and MPLS L2 VPN are overlay networks.

Idk what you mean with routing instability. Changes to routing as a result of failures are a feature not the problem.

Re: Tailscale has raised $160M

#327
post #316

Earlier quoted context omitted.

Because they don't want your password and as a security company, I applaud that. Account issues, recovery, support that can be manipulated, a single breach or bad password that grants access to their admin interfaces, implementing their own 2FA. And, serious people want SSO anyway, and most people have some kind of authentication they can lean on. You can make a stodgy password login if you want, or you can run a key…

Microsoft was hacked before and I don't trust them but I trust the email provider at the company I work for now what

Microsoft getting hacked proves my point more than you think, they're less likely to get hacked now because they have scar tissue. You're basically saying: "If you ever get hacked your reputation is burned forever, but I want these guys who have never done it before to handle logins for me even though they are saying that they are not comfortable with the extra responsibility". Get over yourself.

If you trust your email provider: Ask them to set up an OIDC provider then.

Email is insecure. I can't be the first person to tell you this.

Multiplying your logins is not more security, it's less in the majority of cases.

Re: Tailscale has raised $160M

#328

Earlier quoted context omitted.

I didn't mention Tailscale. I said "overlay", and both SD-WAN and MPLS L2 VPN are overlay networks.

Idk what you mean with routing instability. Changes to routing as a result of failures are a feature not the problem.

You said "Dynamic IP addresses typically also have a forced disconnect at a regular interval.", which is false in pretty much every DHCP scenario I have ever seen.

A change in an IP lease should result in no downtime whatsoever, because addressing is not the same as routing. A routing change would have exactly the same effect on a static IP.

I then pointed out that an overlay network means you don't have to worry about that anyway.

I think you need to reread whatever comments you think you are responding to, as there is clearly something out of sync with your replies.

Re: Tailscale has raised $160M

#329
post #168

Earlier quoted context omitted.

There might be other things going on in the US that you could maybe possibly have heard about, and investors are looking for different places other than the US stock market to invest their money, and Tailscale is looking to have a war chest because of the exceedingly possible case that we're headed into a global recession.

Aren’t they Canadian though?

All the more reason to invest!

Re: Tailscale has raised $160M

#330

I just this past weekend was looking into setting up a personal networking solution- and looked hard at TailScale and their competitors. I do not like- that Tailscale has chosen to only allow SSO sign-in - as that forces one to have a Microsoft,Github[MS], Google, or Apple account- and I presume that leaves one at the mercy of those companies for the free option. I will probably eventually cave and use my main accoun…

t weekend was looking into setting up a personal networking solution- and looked hard at TailScale and their competitors. I do not like- that Tailscale has chosen to only allow SSO sign-in - as that forces one to have a Microsoft,Github[MS], Google, or Apple account- and I presume that leaves one at the mercy of those companies for the free option.

What is going on with your sentences man.

Post reply on HN