Live data from Hacker News

Tailscale is pretty useful

blog.6nok.org

401–410 of 419 posts

Re: Tailscale is pretty useful

#401
post #319

Earlier quoted context omitted.

Great insights, I think you will like OpenZiti, Anders, which is included in your list for both itself and zrok, which we built on top. Directly answering your concerns: - Deny by default and least privilege model means getting access to a node does not give you access to all services on the overlay. This includes SDKs so that only embedded apps are authorised, the apps have no listening ports on underlay and are lit…

I love what you're doing with OpenZiti. I've looked at it multiple times, and I always come away feeling like it's not a good fit for me, and indiehosters in general. I think the concept of making a simple SDK for embedding tunneling in apps is unique and very compelling. However, for me to commit to a platform like that, the most important question is: if upstream changes their license, runs out of money, or just ge…

Thanks for the feedback, tons in there.

- Agreed. OpenZiti is not trying to focus on indie hosts. It has the goal to completely transform how networking and connectivity are done, to make secure by default and a simple user experience the de facto standard.

- Our path to do this definitely depends on monetising enterprise rather than indiehosters. That said, you can build abstractions on OpenZiti, which are much more simple and focused on indie hosters. A good example is zrok (https://zrok.io/), which makes sharing super simple (publicly, privately, and more), and is built on OpenZiti. Likewise, it's FOSS and permissively licensed under Apache 2.0 while also having a free SaaS.

- Likewise, we truly do believe in the power of app-embedded to transform networking and connectivity, but I would note the majority of people (self-hosters and enterprises alike) today use it as a superior private connectivity platform rather than for the app-embedded. They may use the SDKs, or consider it in the future, but the main selling point is the power of the platform, making it dead simple to do private connectivity across networks while abstracting away a lot of complexity (no need for VPNs, SDWAN, inbound ports, complex ACLs, L4 load balancers, public DNS, etc).

Re: Tailscale is pretty useful

#402
post #319

Earlier quoted context omitted.

Great insights, I think you will like OpenZiti, Anders, which is included in your list for both itself and zrok, which we built on top. Directly answering your concerns: - Deny by default and least privilege model means getting access to a node does not give you access to all services on the overlay. This includes SDKs so that only embedded apps are authorised, the apps have no listening ports on underlay and are lit…

I love what you're doing with OpenZiti. I've looked at it multiple times, and I always come away feeling like it's not a good fit for me, and indiehosters in general. I think the concept of making a simple SDK for embedding tunneling in apps is unique and very compelling. However, for me to commit to a platform like that, the most important question is: if upstream changes their license, runs out of money, or just ge…

> "feeling like it's not a good fit for me, and indiehosters in general."

Maintainer here so I'm gonna be biased with this hot take, but I really don't agree with this particular sentiment.

I would turn it around instead and say that most indie hosters are maybe not looking for the levels of protection a zero trust overlay network provides. That is a believable reason for me why it might be perceived as not a good fit. If you're not looking for the sort of security that OpenZiti affords the operator, it will certainly feel less of a fit than a classic VPN-like solution. It also focuses on a different paradigm wrt connectivity centered around individual services. That does mean the learning curve is absolutely steeper because it's not "just IP" and all our years of ip-based-know-how are useful, but not to make the most of the system. While one can use IP/L3/L4 just fine with OpenZiti, it's certainly not trying to be an IP-based VPN (like many of the other solutions are). That also might lead to feeling like it's not a great fit.

For the people who want the sort of security OpenZiti provides, however. It really is an easy-to-use (my bias showing) solution that plenty of indie hosters use already. :)

Not trying to sound too defensive here (a little is ok, right?) but I also appreciate the comments and feedback, thank you!

Re: Tailscale is pretty useful

#404
post #114

Earlier quoted context omitted.

It's functionally just a VPN. Selfhosting wireguard or openvpn is not particularly difficult.

No it's not the same as normal wireguard with some 'just works' config sauce. Devices can connect directly and also find the best way to do it. For example two devices in the same office will create a direct path between them without having to go through the off-site vpn server. At this mesh vpn is really good.

I know it's not just wireguard. That's why I said it's 'functionally' just a VPN. For the average user, it provides VPN-like functionality

Re: Tailscale is pretty useful

#406
post #6

I was once in South Africa and needed to look up my prescriptions in the CVS app. I had lost my pills and needed to show a local pharmacist what I needed. CVS geoblocked me. Luckily I had a TailScale exit node running at home, which solved the problem.

Alternative: OpenVPN server on your router.

Counterpoint: CGNAT

Re: Tailscale is pretty useful

#408

Earlier quoted context omitted.

The Nebula Android app is not open source:( That's why I dropped it, personally. https://github.com/DefinedNet/mobile_nebula/issues/19#issuec... https://github.com/DefinedNet/mobile_nebula/issues/142

Source Available vs Open Source on a monetizable/enterprise component? There are worse tradeoffs one could make, but thanks for pointing it out!

Huh. Y'know, until you suggested it, it hadn't occurred to me that the mobile app could be monetizable. That could at least explain why they did that; I thought it was odd.

Re: Tailscale is pretty useful

#409

Earlier quoted context omitted.

Do mainstream consumers really need a VPN?

Tailscale isn’t really a VPN, it’s an OSI layer 5 for the TCP/IP world. It makes connectivity as easy as 90s LAN parties were. I use Tailscale - so I can do remote tech support on my 81 year old mother’s computer - So I can remote in to my desktop from anywhere with my mobile phone or iPad or Vision Pro or Steam Deck if I need a file or need to print something - watching streaming media from my home network when I’m…

Yeah I mean that's all good stuff, but I just don't see mainstream consumers having a need for all of that. Barely anyone even has a desktop anymore.

Re: Tailscale is pretty useful

#410

Earlier quoted context omitted.

> when my home fiber was installed I live in an apartment. The router was here before me.

Ah, haven’t lived in an apartment since the late dialup era (2005). No sticker on the bottom with login info? Could you exchange it with the ISP? I’m sure you have tried these, just spitballing about how I would try to deal with that…

Anything that's more effort than using tailscale isn't worth it to me. I just treat it like public Wi-Fi that no one but me uses.

My frustration is that it's difficult in the first place. I shouldn't need to call someone (and hope they both comprehend and help) just to configure a device inside my home. It's absurd, and everything that led us to this point deserves criticism.

Post reply on HN