Live data from Hacker News

The New Internet

tailscale.com

41–50 of 315 posts

Re: The New Internet

#41
> Every device gets an IP address and a DNS name and end-to-end encryption and an identity, and safely bypasses firewalls.

Tailscale can certainly be blocked on NGFW firewalls like Palo Alto. I am not a BOFH, but also can’t have random employees circumventing security policies by setting up tailscale and leaving permanent backdoors in my corporate network.

I remember the good old days when everyone had a public IP on the Internet and how easy it was to setup things. It was cool and fun while it lasted. But now things are different and security is a nightmare when we have to deal with things like ransomware.

Re: The New Internet

#42
post #24
post #22

Earlier quoted context omitted.

I was curious why the article didn't mention IPv6 at all, since Tailscale does support it. IPv6 -together with WireGuard- gives privacy, security, and performance. The downside is the complexity to set it up. Tailscale builds on the shoulder of giants. IPv4, WireGuard, Samy Kamkar NAT punching, OpenSSH, and probably many more. One of the upsides is the combination of these, and that the management interface in genera…

Apenwarr is kind of an IPv6 hater. He thinks it's not going to happen.

There are some very valid points here though:

https://apenwarr.ca/log/20170810

Re: The New Internet

#43
post #14
post #13

Earlier quoted context omitted.

100.64.0.0/10 is a reserved IP block for carrier-grade NAT.

More info about Carrier-Grade NAT (for others who, like me, are only encountering this term for the time): https://en.wikipedia.org/wiki/Carrier-grade_NAT Can anyone elighten me regarding what is different or special about 100.64.0.0/10 vs say, 192.168.0.0 or 10.0.0.0. Edit: Answered my own question by digging into more wikis, there is a helpful table of reservations and intentions here: https://en.wikipedia.org/wiki…

> Can anyone elighten me regarding what is different or special about 100.64.0.0/10 vs say, 192.168.0.0 or 10.0.0.0.

A bit of context: if an ISP cannot get enough IPv4 addresses for the WAN-side of people's home routers, some problems exist:

* something in 192.168/16 is generally used for the LAN-side of people's home routers, so that cannot be used on the WAN side

* 10/8 is used for business/enterprise corporate networks, so it also cannot be used on the WAN side because if people VPN connect to the corporate, then the router may get confused

* similarly for 172.12/12: often used for corporate networks

So the IETF/IANA set aside 100.64.0.0/10 as it had no 'legacy' of use anywhere else, and is specifically called out to only be used for ISPs for CG-NAT purposes. This way its routing does not clash with any other use (home or corporate/business).

    IPv4 address space is nearly exhausted.  However, ISPs must continue
    to support IPv4 growth until IPv6 is fully deployed.  To that end,
    many ISPs will deploy a Carrier-Grade NAT (CGN) device, such as that
    described in [RFC6264].  Because CGNs are used on networks where
    public address space is expected, and currently available private
    address space causes operational issues when used in this context,
    ISPs require a new IPv4 /10 address block.  This address block will
    be called the "Shared Address Space" and will be used to number the
    interfaces that connect CGN devices to Customer Premises Equipment (CPE).
* https://www.rfc-editor.org/rfc/rfc6598.html

Re: The New Internet

#44

> Every device gets an IP address and a DNS name and end-to-end encryption and an identity, and safely bypasses firewalls. Tailscale can certainly be blocked on NGFW firewalls like Palo Alto. I am not a BOFH, but also can’t have random employees circumventing security policies by setting up tailscale and leaving permanent backdoors in my corporate network. I remember the good old days when everyone had a public IP on…

Tailscale doesn't even try to hide their MP or DP traffic. Last I checked, management was plain https and data was plain wireguard.

Re: The New Internet

#47
post #24
post #22

Earlier quoted context omitted.

I was curious why the article didn't mention IPv6 at all, since Tailscale does support it. IPv6 -together with WireGuard- gives privacy, security, and performance. The downside is the complexity to set it up. Tailscale builds on the shoulder of giants. IPv4, WireGuard, Samy Kamkar NAT punching, OpenSSH, and probably many more. One of the upsides is the combination of these, and that the management interface in genera…

Apenwarr is kind of an IPv6 hater. He thinks it's not going to happen.

> Apenwarr is kind of an IPv6 hater. He thinks it's not going to happen.

Well, T-Mobile US is 100% IPv6:

* https://www.youtube.com/watch?v=QGbxCKAqNUE

Facebook is IPv6-only on their internal infrastructure:

* https://www.internetsociety.org/resources/deploy360/2014/cas...

Microsoft has been moving to IPv6-only for their corporate network (so IPv4 address can be used for revenue-producing Azure):

* https://www.arin.net/blog/2019/04/03/microsoft-works-toward-...

So he better tell those folks that IPv6 is not a thing.

Re: The New Internet

#48
post #24

Earlier quoted context omitted.

Apenwarr is kind of an IPv6 hater. He thinks it's not going to happen.

There are some very valid points here though: https://apenwarr.ca/log/20170810

Here is a list of of proposals for what could have replaced IPv4:

* https://www.rfc-editor.org/rfc/rfc1454.html

Here are the technical criteria for choosing the (then-labelled) IPng:

* https://datatracker.ietf.org/doc/html/rfc1726

And finally the evaluation of the available candidates and why the winner was chosen:

* https://datatracker.ietf.org/doc/html/rfc1752

If someone doesn't want to use IPv6, then what they're effectively suggesting is that we create a new protocol, and role it out to every smartphone, tablet, laptop, desktop, server, (Wifi) router/CPE, ISP router, SMB router, enterprise switches, and IoT device. Meanwhile we've already effectively run out of IPv4 addresses (e.g., ARIN and RIPE pools are zero) and are just shuffling about whatever is left in auctions.

> There's one thing I forgot to mention in that big long story above: somewhere in that whole chain of events, we completely stopped using bus networks. Ethernet is not actually a bus anymore. It just pretends to be a bus. Basically, we couldn't get ethernet's famous CSMA/CD to keep working as speeds increased, so we went back to the good old star topology.

Except for 802.11 Wifi.

Re: The New Internet

#49

As I've been deliberately moving toward self-hosted computing, under my control, on my home network , I've had a feeling more and more that we're on the cusp of something transformative... For those who want it and those who care. There's an ecosystem of mostly FOSS software now designed to run on a home network and replace big, centralized, cloud providers. That software is right on the edge of being easy enough for…

> As I've been deliberately moving toward self-hosted computing, under my control, on my home network

Funnily enough, I was once like this but now I have deliberately moved everything to the big cloud providers as I don’t want to deal with the toil of running my own homelab anymore. This is coming from someone who used to have a FreeBSD server with ZFS disks and using jails to run various things like pf, samba, etc. Eventually things would fail and it felt like I was back at work again when all I want to do is drink a cold beer and watch YouTube.

Perhaps I will try again one day as things get easier. For now I am content with having my photos and videos automatically synced up to iCloud/Google Photos.

Re: The New Internet

#50

> In fact, we didn’t found Tailscale to be a networking company. Networking didn’t come into it much at all at first. I always just assumed they were building some kind of logging software (“tail”scale), used Wireguard to connect hosts, and just kind of stopped there. Don’t get me wrong, Tailscale is a nice way to connect machines. It’s nice because Wireguard is nice.

https://apenwarr.ca/log/20190216

This long blog post (by the now-CEO of Tailscale), if you skip to the end, describes that parent’s hypothesis is basically exactly correct.

> Update 2019-04-26: Based on a lot of positive feedback from people who read this blog post, I ended up starting a company that might be able to help you with your logs problems. We're building pipelines that are very similar to what's described here.

Update 2020-08-26:

Aha! Okay, for some reason this article is trending again, and I'd better provide an update on my update. We did implement parts of this design for use in our core product, which is now quite distinct from logs processing.

After investigating the "logs" market last year, we decided not to commercialize a logs processing service. The reason is that the characteristics we want our design to have: cheap, lightweight, simple, fast, and reliable - are all things you would expect from the low-cost provider in a market. The "logs processing" space is crowded with a lot of premium products that are fancy, feature-filled, etc, and reliable too, and thus able to charge a lot of money.

Instead, we built a minimalistic version of the above design for our internal use, collecting distributed telemetry about Tailscale connection success rates to help debug the network. Big companies can also use it to feed into their IDS and SIEM systems.

We considered open sourcing the logs services we built (since open source is where attributes like cheap, lightweight, etc tend to flourish) but we can't afford the support overhead right now for a product that is at best tangential to our main focus. Sorry! Hopefully someday.

Post reply on HN