It's designed to be as minimal-configuration as possible and scalable in a way that many other mesh routing protocols aren't.
It's designed to be as minimal-configuration as possible and scalable in a way that many other mesh routing protocols aren't.
YG is decentralized, direct peer to peer and multi hop routing, manual key exchange for direct peering, virtual internet (each node is a router to another nodes)
ZT (and Tailscale) requires a central node coordinator for automatic config and peer key exchanges, peers directly to each node to create a flat virtual network, not multi hop routing, between two peers you need a reachable IP or port mapping (supports UPNP) by one of them (fixed in config there are private TCP relays when carrier NAT/double NAT/ restrictive firewalls are in place, very slow), Uses UDP for the links, mimics a virtual switch and support custom IPV4 / IPV6, good for virtual private networks.
YG (and CJDNS) is kinda an overlay public network, is fully decentralized, it supports automatic routing between nodes to mimic a virtual Internet, each node is a router too, needs to register each key for every direct peer node connection (config needs peer key, reachable ip and port, but supports automatic key exchange for local networks), YG uses TCP for the links, support self-healing routing, every peer has an IPV6 address derived by its public key.
ZT (and Tailscale) can mimic a mesh network and node routing because supports bridge nodes between networks (routing between virtual switches), but is not self-healing and somewhat heavy work to config. ZT is fully open source, can be config with your own node coordinator and discovery helpers (Controllers and Moons in ZT), not easy. Only Taislcale client is open source, can't be config with your own node coordinators for free.
You can mix ZT and YG, weird side effects warranted but works. (Edited post - some grammar fixes)
It's closer to bittorent than a VPN. It has end-to-end encryption and each node (the app that runs on your PC) distributes routes to each other (similar to how routing works on the Internet between large networks). It appears to be a flat spanning-tree style network.
They mention that it is using similar code and ideas as the cjdns project.
I use yggdrasil for NAT hole punching my VPN, for example.
>People often ask us for an overview of how Tailscale works. We’ve been putting off answering that, because we kept changing it!
Yggdrasil is fully peer to peer and doesn't require a central coordinator like tailscale does. Ygg is closer to a global network than a private one. You can make a private network, but if any peers on the network peer to the global net then your whole network is now peered. this should be handled at the firewall level, or with an overlay VPN.
I still facepalm whenever I think about this.