Tailscale has reached general availability
tailscale.com
tailscale.com
GSuite is easy to justify for me. Github is. JIRA is. Tailscale is more expensive than all of them and it's hard for me to make the case, even to myself, that it's worth it.
I'd like to ask Tailscale to think about alternative pricing models of maybe $20/month per admin account, which comes with 10 bundled "member" accounts or similar. That would get me to $40 or $60 a month, which I can stomach. But I won't pay $300+/month to save myself a little bit of inconvenience every few weeks so my devs can securely log into our servers.
I'd love to hear more of your thoughts on where you think we can add value and what it might be worth to you. If you're up for it, please email me at dfcarney@tailscale.com Regardless, thanks again for the input.
It sounds like a great product, but it would definitely have less value to us than the above products.
That seems to set a price ceiling, but of course, you're free to find the price elasticity curve by exploration...
Honestly, the customer in mind is not the startup with bootstrapped money. $10 a month is what people pay for a Netflix subscription, but this stuff is quite valuable. I think they may offer special plans for the poor, ailing startups but I don't see ANY reason to complain about their service.
Something that bugs me about ZeroTier is also present here, which is that there's no name management whatsoever, so I have to either keep a hosts file around with all the names of the network or find a script on GitHub that does it for me (or put a DNS server on the Tailscale network, and make sure all the hosts have records on there manually since there isn't a way to automatically integrate it with the hostnames that Tailscale already logs). Or, of course, use public records and pray you don't have more than a couple services because who wants to log in to the domain host every time you bring up a new container?
Half the magic of BeyondCorp (which I'm a big believer in) is that it's invisible from an end user perspective. I open a browser, go to git.corp.planeteaston.com, and it works, not "let's go to gitlab... it didn't resolve. what was the IP address again? 192.168.10-oh, wait, I'm offsite, the address is different, let's go see what it is in the Tailscale console", and a tech person could figure that out, maybe, never mind a computer-illiterate person in another department that was just told "go home, coronavirus, take your laptop".
This isn't a knock, since the main competitor, ZeroTier, doesn't have a great solution for DNS either besides run a DNS server, but whoever cracks it will probably win this race. And it's almost worse for ZeroTier, which by default (at least when I started using it 2-ish years ago), wanted you to use IPv6 addresses by default that there was no chance of you memorizing. I'll be a customer when this works!
We are working on it as soon as we ship 2.0, which is a huge undertaking that's taking longer than we hoped. 2.0 has a ton of important improvements including but not limited to professionally audited design and code (not revealing the security firm yet but they are extremely well known). Just finished our first round with them. (Bonus: our existing design is not bad and it won't take much to harden it a lot more.)
As someone who's been following tailscale's development, I'm curious to what you mean by core routing? Isn't routing P2P? Or, do you mean routing via DERP tunnels or TURN relays when P2P is a no-go? If so, what really are some key challenges here?
I suppose ms windows servers are still lagging on mDNS, though?
Also, being able to ping my iOS phone that's on 4G from my computer feels like magic.
So, like every other VPN?
As well as the one from the author of ntop.
A few characteristics most projects consistently fail to meet are (a) keeping the source code available, small, relatively simple and easy to compile, (b) allowing peers the option to connect directly after discovery without routing traffic through a third party and (c) recognising that not all peers want to form massive infinitely scalable networks, most will prefer small ones.
Most P2P projects choose a design that forces the majority of users compromise in order to accomodate a few unpredictable/hypothetical edge cases. "Perfect" gets in the way of progress. History shows there is no "perfect" when it comes to P2P.
We know we keep getting feedback that people want a different way to authorize their accounts (especially for personal use), so we're looking at other options. We just really want to stay out of the username+password business; it's simply bad security practice.
And you don't get any key rotation unless you force people to change their passwords occasionally, which is itself now deprecated as a bad practice because people then start writing their passwords down on paper or storing them in a spreadsheet, which is even worse than no rotation. (Tailscale rotates your VPN keys automatically, but it's all for naught if the root key is just a password.)
We know that something better is needed for personal accounts, but please, not username+password. Your private network security is important. The world needs something much closer to foolproof.
I'd be very surprised if this was true. Most all technical (competent) people I know use a pw manager of some sort
Unfortunately non-technical people mostly don't use a password manager and we can't assume they do. Tailscale is about making the Internet secure by default, and passwords will never be secure by default.
FWIW, we'll probably also be supporting GitHub (and maybe Twitter?) auth, as well as perhaps letting you run your own auth server if you set up the right DNS records. Lot of things yet to do.
On the other hand, I really like Keybase's way of federating multiple identities together, where each additional identity provider increases rather than decreases confidence.
If your highest concept of identity is the account and identity managers allow you to authenticate to that account, let's say you have a tailscale account with id 123, and any human who has access to john@personal.org or john.smith@job.com can access that account.
What do you do when John leaves job.com? Can John (accessing the account through john@personal.org) still admin the job.com bits?
I think the right abstraction is having first-party (in this case tailscale) accounts belonging to one or more "teams" and authenticating with a @job.com address allows you to switch to the job.com team in the UI / allows you to generate API creds that modify job.com's team.
Sign in with Apple works natively on iOS, macOS, tvOS, and watchOS. And it works in any browser, which means you can deploy it on your website and in versions of your apps running on other platforms.
So it at least sounds like it can be used anywhere with a web login flow. Although the docs say this must be accomplished using their JS library, as opposed to a standard OAuth2 flow of some kind: https://developer.apple.com/documentation/sign_in_with_apple
I really want to give you guys money for my personal use but $10/user/month is steep when I know the other users will only use it once it a blue moon (but of course, when they need it they'll REALLY need it).
If there was something like a "supporter plan" that was similar if not identical to the free plan but charged a flat fee, I'd be all over that.
In the meantime, it's fine to be on the solo plan for personal use, it's there and free to be used :)
Personally I want ZT to integrate support for integrated (e.g. Apple security chip) and discrete (YubiKey etc.) secure tokens and enclaves. That is where the real security is at.
Looks very nice and clean.
Glad you like it! The text styles are custom, and the layout is built using an in-house CSS framework not unlike Tailwind [1].
But if you'd like to build something similar, you could get pretty close by using something like Tailwind and building with Rasmus Andersson's lovely (and open-source!) Inter type family [2], which we use throughout the site.
thanks for your reply and great work:). The site looks just amazing and very clean (especially typography). I noticed it uses utility classes like tailwindcss so thought maybe there is a similar library.
I wish one day Tailscale allows private relay server, for privacy and speed / latency reasons.
Still, for latency and compliance reasons, it makes sense to allow companies to operate their own DERP relays, if they want to.
I'd certainly be interested in a blog post about this, if it's as easy. But considering that Tailscale took this long to launch, I have doubts that this is as easy to build.
My teammate Dave Anderson is writing a post about all the insanity that is NAT traversal. That alone will probably be as long as this entire article. Stay tuned!
I've watched countless p2p projects fail due to NAT difficulties, and spent months/years banging my head against it only to fail too. I've heard that NAT is tragically still a thing with IPv6 as well.
Please, if you all make it big, start a cross-platform open source, drop-in library that completely solves the NAT problem. The unit test for it would be that an app using it can accept inbound connections with zero configuration. That might require a central server though. I think the crux of the problem is how to share IP addresses with each other through that central server securely for STUN/ICE so that nobody can eavesdrop. Would you consider making your DERP servers free and open for that purpose? Apologies if I'm glossing over this or missed something, this is just something that has vexed me for almost 20 years. Thanks!
Completely solving NAT... I've tried a couple of times over the last 10 years, bunch of false starts. You can see one of the older attempts at https://github.com/danderson/nat (don't use it, it's very basic and fails at a lot of NATs). One of the tricky parts is that to make it work right, you really need control of the wire protocol you're using, because you have to inject frames and do all kinds of weird things to help with the NAT part, while ignoring all that noise at the "upper protocol" layer. You can make it generic with some careful layering, but it turns a simple API into a complicated one.
You absolutely need a coordination server for NAT traversal to work. That's unfortunately one of the great unsolved problems for fully decentralized p2p. But it can be _any_ low-bandwidth channel you have available (one of my first implementations piggybacked over XMPP messages), and it doesn't have to be a trusted part of the system (although making it trusted simplifies a ton of stuff). And you also need some kind of data plane relay (like DERP) for when NAT traversal fails, which still happens a fair bit. Without that extra layer of relaying, you'll only ever hit 95-99% connectivity, not 100%.
I'm (slowly) writing an article on NAT traversal that covers all this. It's a thorny problem, and I'd love to solve it once and for all (which is sort-of why I work at Tailscale - I think I have a shot of solving it once and for all at the IP layer, so that all the other layers can just stop caring)
With Tailscale we want to take full responsibility for connectivity, so that app developers can work on apps that just assume the connectivity+security is there, and users can complain to us instead of them when their computers won't connect. At least, that's the dream. How best to package that up, I'm not quite sure.
Regarding DERP, the server code is open source: https://github.com/tailscale/tailscale/tree/master/cmd/derpe... and if you look closely, you can see that DERP servers are fully anonymous (pseudonymous?) and will route traffic between any two DERP connections based on their public keys. We rate limit traffic to keep costs under control, and we'll let paying customers boost their speeds, but we intend to always let our DERP network be usable at "reasonable throughput" for free. And since the code is open source, you can write your own tools that do it.
Lots of things to work on. Hope this helps!
This looks very similar to ZeroTier - apart from building on wireguard - how do the solutions differ? Is tailscale also a true mesh (ie packets go direct between two tailscale nodes on a lan)?
I'm curious if it'd be possible to avoid using brands by just authorizing device ids like Syncthing does, without any login at all.
Bonus points if you call the plan, the wireguard plan; and 90% of the payments go to Jason Donenfeld.
We've been exploring the idea for a free (or significantly discounted) "family" plan (or even something like that for small teams). Please stay tuned over the coming weeks for some updates to our pricing and tiers.
I am getting intermittent errors in the dashboard as well.
As for alternatives, we tried chat but no-one used it, and it added a ton of heavy awful javascript to our website. You can file issues on https://github.com/tailscale/tailscale, though for the dashboard I'll move them elsewhere. Also we have been looking at various pieces of "forum" software too but haven't settled on anything we really like.
Could you elaborate on the errors you saw? If you want to send support@ an email with your account email address and rough time, I can look in the server error logs and try to hunt it down. Thanks.
(I work on Tailscale.)
> We’re announcing our public launch today, with a $3M seed round →
Seed rounds are now 3M, wow!
I wonder how they seemlessly authenticate with Okta, Google, Active Directory e.t.c ?
I was interested in WireGuard for a while, but setting it up properly seemed rather a daunting task to me. With Tailscale, this was literally a matter of minutes. I'm not sure I would pay $10/month for this, but the free solo plan is sufficient for my purposes and works great.
HN simply favors some founders who have good network over the rest of us. I know that organized upovting and astroturfing isn't uncommon here, but there has never been anything anywhere near that's being done by this company and its founders here. This is simply free advertising worth of hundreds of thousands of dollars for free simply because the founders "know people".
EDIT: Thank you HN for proving me right! This comment has 42 points as of now and it's buried in the bottom below almost every other comment. Still not a response from the founders who very coincidentally happen to exist literally during every time a post about their company gets submitted!
You've been proven nothing of the sort. I buried your post and the submission itself while investigating this claim, even though you've been trolling HN threads with these rants for weeks now, using multiple accounts to do it, ignoring our requests to stop breaking the site guidelines, and barraging us with ranty emails to boot.
I've looked closely at the data and found no evidence for any of this. Every sentence in your comment is either demonstrably false or completely unsupported.
I know that sometimes a bee gets into one's bonnet, but as I've explained to you a dozen times or so, all we can do is look at the data, and if reality conflicts with what you're saying, we have to go with reality. Actually, I appreciate your underlying concern for the integrity of this site. (Not so much the smears and accusations of corruption.)
Your real sin, though, is wasting our time. That sucks precious resources away from doing what we ought to be doing to make HN better. I haven't had a chance to attend to the front page for the last several hours because I've been busy looking into this, writing about it, and dealing with your posts and emails. Meanwhile other emails pointing out quality concerns in other threads have been piling up in the inbox.
Even though it's tedious, I've assembled a sample of what you've been posting so that readers can evaluate your claims for themselves, and also see how much damage a single disgruntled user can do to this place. In the future, we can refer concerns back here and hopefully not lose so much time.
https://news.ycombinator.com/item?id=22465402
https://news.ycombinator.com/item?id=22645796
https://news.ycombinator.com/item?id=22587268
https://news.ycombinator.com/item?id=22646808
https://news.ycombinator.com/item?id=22223423
This was a pleasant one: https://news.ycombinator.com/item?id=22652042
In the past, you've had similar campaigns against other sites and topics, including Go, Kubernetes, IndieHackers, Keybase, DuckDuckGo, Mailchimp, and (yes) the Qataris:
https://news.ycombinator.com/item?id=22361860
https://news.ycombinator.com/item?id=22329624
https://news.ycombinator.com/item?id=22190633
https://news.ycombinator.com/item?id=22211243
https://news.ycombinator.com/item?id=22109987
You can check a lot of this for yourself using publicly available information.
Look at a sample of users who've been expressing interest about Tailscale, in threads about that topic and/or Wireguard or other topics. Check out the histories of these users—you can do that by clicking on a username to go to their profile, and then clicking on 'comments' or 'submissions'. You'll see that most are longstanding, serious community members. If your random samples look anything like the ones I've examined, you'll find many excellent HN contributors among them, with a lot of technical expertise. This is evidence that the interest in this topic is both organic and serious. I'd supply links, but it wouldn't feel right to haul in specific usernames that way. It's easy enough to check.
To that public information, I can add some non-public facts. First, the profiles of users upvoting these threads look much the same as the commenters. Of course in many cases they are the same, since it's natural to both upvote and comment on something that you find interesting. In addition, the voting patterns on these threads look like what we see on popular topics of organic interest, and nothing like what we tend to see with voting rings and organized promotion.
Conclusion: although we can never say for sure, because we aren't inside users' heads while they upvote, the evidence points to organic interest. I'll go further: I'm the person who has spent by far the most time on this problem in the history of HN and I find it hard to imagine the evidence being any clearer. Also, no one at HN (and no one at YC that I know of) has any connection with any of the people involved in this project. I've spent so much time writing about this because (a) I don't like to see people smeared, (b) we take concerns about abuse of HN extremely seriously, and (c) I want a record to link back to in the future so I don't have to spend any more sad hours on this.
I'm a HN user who regularly looks for patterns like connected accounts, weird upvote or comment behaviour in /newest, fake news, bots and reports those to the moderators.
Until today I haven't known about Tailscale, or not conciously remember the brand name. Every past article listed I would've probably upvoted. It fits with the HN audience, just like Docker, ElasticSearch, Cloudflare, gitlab or most polished SaaS companies targetting developers when they release a new major feature. There will always be a commercial/marketing component when companies release something, even more when a founder or employee answers questions in comments. Doesn't mean there's some kind of secret community who upvote each other. Or rather if there was the moderators, once notified, would've found and acted on that.
They are then building the security model that Google uses[0], but trying to get it to other companies. I think the concept of BeyondCorp is pretty amazing and a great way to think about trust on a network.
Those 2 points together probably gets them lots of upvotes.
I looked via a simple algolia search for "tailscale" and found relatively minimal posts but also a number with very few upvotes: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
I don't hate on people for doing similar things. If anything I am absolutely shocked it took someone this long, since to me the idea of a full mesh virtual network is how things should work, everything else is stupid and clunky, the fact that we have to bounce off servers to transfer things is dumb, and NAT is pure concentrated evil and must be destroyed.
I absolutely loved David Crawshaw's Remembering the LAN post:
https://crawshaw.io/blog/remembering-the-lan
It echoes exactly the sentiments that motivated me to start working on ZeroTier, so I wish them well.
As far as the upvotes go I just figured they have a lot of friends from their time at Google and their posts get upvoted a lot.
I notice the same thing when any company that has a lot of HN users among its employee base does anything. When AWS, Apple, and Google do a bunch of product releases the front page gets bombed for days. The site practically turns into a news feed of new AWS Elastic Beanie Cap products when the ironically titled AWS ReInvent happens. If anything the FAANG companies get more free advertising here than anyone.
Because it's really hard to monetize it. Speaking from the experience.
Edit - This particular bicycle gets reinvented on regular basis and in a nearly identical form. While technical details are difficult, the overall idea is rather simple. Rendezvous servers to coordinate the setup and NAT traversal + relays to handle the edge cases. The tricky part is the UX... but it's still nothing compared to monetization. Very few end users will pay for this, because if it "just works", it doesn't look like something worth paying for. Smaller companies will pay, but they don't realize they need it. Larger companies realize the need, but they won't touch 3rd party managed VPNs with a long pole. It's really quite a pickle. But the tech is beautiful :)
I'll give what I think are my reasons:
- It's "easy" to do a proof of concept here, but it's brutally hard to make it really work well and at scale. There are a lot of buggy NATs, highly restrictive firewalls, etc. Network virtualization, which is what you need for it to be general purpose rather than app specific, is another layer of difficulty.
- It's hard to do it securely. Anything that gets popular will get attacked a lot and has to stand up against that. It's easier to secure centralized systems against most attacks for multiple reasons.
- The dominant paradigmatic fads from 2004-2019(ish) were cloud and mobile. Cloud obviates the need for this (in exchange for all privacy and freedom), while early mobile devices and mobile data options were too wimpy to do P2P. The latter is still a problem but less so today than 5-10 years ago.
- Most P2P software has had poor usability, slowing its adoption.
- The cryptocurrency bubble sucked all the air out of the decentralization room, causing the entire notion of P2P and decentralization to get conflated with CoInZ. That seems to be ending.
The main issue is that the need is not well-defined and there are competing solutions that aren't as technically elegant, but as robust and as easily deployed. Competing with them on _P2P_ basis only is really hard. The only real technical benefit is lower latency... and even that may not hold true in aggressively shaped consumer networks. It used to be possible to get a bit of an edge from having near-zero hosting costs, but that's been far less relevant for a while now.
I, for one, really appreciate the nod. I agree our motivations align and I look forward to hearing more about what you and team come up with. All the best on things at ZeroTier.
When I make a comment, my username is displayed. If upvotes and their timestamps were public, it would make it a lot easier for the community to get to the bottom of any funny business like OP is describing.
EDIT: Slightly altering it a bit. What if only the first 50 upvotes were public?
Hell they could just tag articles related to YC companies with a special color and pin them for a bit. I'd be fine with that.
There are three formal things that HN gives back to YC in exchange for funding it: (1) job ads, which appear on the front page and later on https://news.ycombinator.com/jobs; (2) Launch HNs for YC startups, which appear on the front page and later on https://news.ycombinator.com/launches; (3) YC alumni usernames display in orange to other YC alumni (though not to themselves, which has led to a stream of emails over the years).
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
We explicitly don't do anything beyond that to favor YC or YC companies on HN, though we don't draw lines to exclude anything either, because YC-related people and content are an inseparable part of the community here.
I really need to add this to the FAQ though.
e.g. if you're someone who routinely upvotes posts within minutes, maybe your vote could count for less than an account that only dips in to the new page occasionally?
Or maybe your vote gets penalised if it's your only upvote in a 24 hour period?
Or maybe HN keeps track of who you upvote with, and your vote gets penalised the more you upvote with the same people?
idk, it sounds like a fun project for someone if HN wanted a more organic front page.
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
I've personally spent hundreds of hours working on this, as well as tracking down voting rings of every imaginable sort. I'd never claim that our software catches everything, but I can tell you that it catches so much that I often go through the lists to find examples of good projects that people were trying ineptly to promote, and invite them to do it again in a way that is more likely to gain community interest.
I can see you didn't want to talk about this, esp with the tedious conspiracists. But I'm glad you did, and appreciate your work in keeping HN interesting & fair.
It surprised me because 1) I achieved a moderate position on the front page a few years back "asking a few friends" to upvote something about my former company, but mainly 2) there's no warning to new post submitters as to the values, integrity etc. of the site, to warn people off trying to game it, which I'd expect when you'd put that much work in.
I know there's a minimalist / in-the-know aesthetic to HN but I've been here 10 years, started & sold a tech business, and still didn't know the rules, the moderation patterns etc, other than "by example" (but then who'd want a whole meta.hn forum, gulp).
Out of curiosity, would you be willing to share a link to the post you mentioned that got on the front page? I'd like to see whether our software missed it, and why. You can provide it here or send it to hn@ycombinator.com if you'd prefer a private conversation.
Sometimes the software catches voting rings and we turn the penalty off because the article seems likely to interest the community. It's not perfect, though, and knowing about cases that it missed can be very helpful, since independent verification is usually not available!
the question is, how do we get other interesting posts and products to HN front page?
When the HN plays favoritism in the vein of shilling for Y Combinator portfolio companies they make it fairly obvious to anybody paying attention. The portfolio company hiring posts are an example. Post to job descriptions and commenting disabled.
As I said recently, it's a cat and mouse game and we eat a lot of mice. https://news.ycombinator.com/item?id=21916935
You guys should realize how much work we put into defending this site against manipulation. Especially if you ever find yourself wondering why there isn't much new feature development on HN.
Please stick to this, new features aren't necessary! (You've heard this 10,000x before, but, reinforcing for posterity.
...could you un-shadowban me/whatever the state of my account is right now?
Happy to unban you if you give us reason to believe that you'll use HN as intended in the future. It's best to email hn@ycombinator.com about that.
> No. Users should vote for a story because they personally find it intellectually interesting, not because someone has content to promote. HN's software penalizes submissions, accounts, and sites that break this rule, so please don't.
"A "voting ring" is when people get friends to upvote their stuff. This is against the rules. We want stories to be on HN because they're good, not because they were promoted." [2]
You've now crossed way beyond the point of trolling, including barraging us with hostile emails, and it's time to drop it and move on.
HN can't do much about upvotes coming from friends if they're sufficiently distributed/no patterns to find.
Also, please consider: their posts are just good/stimulate great discussion across multiple sectors of tech (networking meshing applies to ALMOST EVERYONE!).