Even supporting WireGuard's Share Secret feature would be a start.
As long as that's not addressed, not a chance in hell I'm going to deploy this.
Even supporting WireGuard's Share Secret feature would be a start.
As long as that's not addressed, not a chance in hell I'm going to deploy this.
Tailscale was on the list for services to check, but if what you say is true, then I will look elsewhere.
I believe that the free tier is capable of running clusters of up to 50 machines. Really nice to use + truly trivial to set up.
Even bare Wireguard is a joy to set up, to my endless surprise, if you’re fine administering things as a traditional small-scale LAN, manual routing and all.
ZT is vulnerable to this because we actually try to make everything decentralized and self hostable. We are not making a cloud silo play where we try to lock everyone into our hub to do their networking, so we have to be able to monetize by licensing as well as SaaS. Our SaaS is optional.
This wasn’t an issue a decade or two ago when existing FOSS licenses were created. It’s an issue now, and is why other people working on decentralized easy to set up systems like CockroachDB use the same license we do. If CockroachDB were liberal FOSS someone would fork it and slap their name on it and scoop them, since by not having to do the hard work of actually developing it they could focus exclusively on marketing.
(You can self host ZT controllers, and roots become easier to self host in the next major release. Once we do that the protocol could theoretically outlive the company with no loss of functionality including its unified namespace.)
More generally, I like what you said a little while back in the thread about the Mighty remote browser [1]:
> (2) The hopelessly naive idea that "information wants to be free" and everything has to be "free" (as in beer) needs to die, be cut into a thousand pieces, burned, encased in concrete, and sunk to the bottom of the ocean. Nothing is free. Software takes a vast amount of labor to produce, and that must be funded. If it's not funded directly and honestly it will be funded indirectly and dishonestly (surveillance capitalism, cloud lock-in, etc.). "Everything has to be free" and piracy actually help push us toward a surveillance capitalist panopticon future.
That point should be front and center in all discussions on FOSS sustainability (or lack thereof).
You’re absolutely brilliant (like Cloudflare), your goal does not seem evil (similar to that of Cloudflare), neither do the consequences of achieving it (somewhat less like Cloudflare), and you haven’t done outright evil things like patent clever but fundamentally simple tricks (have I mentioned I’m conflicted about Cloudflare?). And when all is said and done, you do have to pay your bills, and only you can say what works and what does not in that respect.
So I applaud you when you say, loudly and honestly, that the goal of your licensing model is to pay for the development by making yourself an essential part of it. I believe you when you say your work couldn’t exist otherwise. But my mental model of (dev– and knowledge-of-humankind–centric) open source (unlike that of user-centered free software) is that its very essence is the original developer making themselves unessential or at least not using legal threats to preserve their special position.
Thus I am explicitly not saying that your non-open-source approach is evil—that would be unjustified purism; morality judgments are difficult and best not employed as one-sided proclamations. I am not expecting that you will go home ashamed or mend your dastardly ways, because you have nothing to be ashamed of, your ways are not dastardly, and I have no idea how you could mend them and still survive. I am saying that your non-open-source approach disagrees with the very core of the open source idea as I best understand it, not on a purist technicality but in a fundamental way.
Bruce Perens co-founded the OSI. He seems to have given up on the idea of open source in the age of mainframe providers wielding armies of star programmers, and probably would not have any issue with your strategy. I am younger and have not given up yet, so I look upon your strategy with sadness and a longing for a better world.
Bruce Perens is much smarter than me in more ways than one.
Closed silos don't have that constraint so they will win by sheer muscle power.
The BSL (our current license) sort of sucks, and I look at it as a stopgap until we can come up with something better. I have some ideas, but they need to be developed and so far I have not had time to develop them further since coding and running a company are fairly demanding.
They deserve a blog post at least.
Outstanding reply BTW.
Please do note that zerotier is still source available (with 2025 - 5 years? Transition to apace Foss license): https://github.com/zerotier/ZeroTierOne/blob/master/LICENSE....
So, AFAIK you can self-host, audit and patch.
(lots of great discussion on Foss vs non-foss, pragmatism etc in this thread, to which I can't add much)
I guess nebula is: https://github.com/slackhq/nebula
Anyone tried it vs zerotier/wireguard/tailscale? I must admit building on wireguard is a major draw for tailscale.
Roots in ZeroTier are harder to self host right now (it’s getting easier in the future) but they are just dumb STUN/TURN equivalents. They have no power to grant access and can’t even see what networks you join or what you are doing.
PRs welcome :)
Do you also manufacture your own silicon in fear of being owned by your hardware vendors?
Write all your own software?
In fear of being owned by zero days in open source?
Security breaches happen every day, with serious consequences. These are real threats, and there are ways to mitigate against them.
A target like that coordination server is particularly risky because, as we saw with the massive Solarwinds attack, attackers will look for and expend effort to compromise the most attractive targets, and that's a particularly juicy one.
Dismissing such threats with false equivalences is a pretty good way to find yourself on the wrong side of a security breach.
Either you trust the entity whose code you are consuming or you don't.
Do you trust WireGuard to not get owned via a supply chain attack? Like Solar Winds.
Do you trust any open source project you currently use to be free from bugdoors? Like University of Minnesota recently demonstrated by submitting intentionally-vulnerable patches to the Linux kernel.
An always-on service is an ongoing, continuous trust relationship with continuous temporal vulnerability
Consequently, while I can reasonably safely apply a lower bar of trust to libraries and code, someone asking to be continuously trusted must be held to a distinctly higher standard.
It is can be valid to trust that as well, but you're operating from a crippled starting point for your security engineering if you don't see those as separate categories of issues to address.
You are lying to yourself.
You are necessarily claiming that a single person (you) is capable of adequately verifying the trustworthiness of the work of hundreds (perhaps even thousands) of developers.
That's just the story you tell yourself to convince yourself that you are in control.
Mean while FAANG have been doing it all wrong by hiring thousands of security engineers. They should've hired you.
Also, this seems backwards to me. You trust Tailscale at the network layer. If they abuse your trust to inject routes/keys your machine becomes network-reachable but all of your other controls are still in tact.
That's not true when you applications violate trust.
You can do AppSec if you don't trust the network. You can't to NetSec if you don't trust the application.
I guess you could split it in half, and pair it with some actual service that the customer runs, and let it just be a dumb relay of encrypted/signed/whatever data.