Add ability to choose a custom coordination server
github.com
github.com
Doing business out in the open like Tailscale is doing is so refreshing. Having seen Brad Fitz communicate in other places, it is obvious he isn't doing the right thing for the user only because these conversations will be scrutinized in public. Tailscale has a lot of great technical people who actually are even better communicators.
This is the lesson for me in this thread: remember to optimize hiring good communicators and not just good technical people. This conversation would have quickly gone south if it was purely about the technical or business reasons for doing it. After all, the root word of communication is commune: to connect. We often forget that.
https://twitter.com/bradfitz/status/566072337020112896?lang=...
The product was a terrible piece of crap that never should have been released.
Short-term (<15minute, repeatable) hush modes are considered a safety feature. They prevent angry homeowners from removing the smoke alarm entirely, a far more dangerous situation than a short term hush.
NFPA 72 recommends a desensitization method for ionization smoke alarms and requires one for smoke alarms installed near a cooking appliance, and several states have followed in codifying this into law. Hush is not required for photoelectric smoke alarms, under the theory that they are less prone to cooking and shower-related false-positives, but this feature is still allowed and they are a common user convenience.
UL 217 allows smoke alarms to be provided with a <15 minute desensitization feature which prevents an alarm from triggering unless obscuration/ft exceeds 4%.
Also... the Nest v2 got an in-app hush feature. My understanding is that V1 had some kind of false-positive issue that triggered a ">4% non-hushable" alarm, though, so this wouldn't have mattered.
Bogle (the father of the index fund) talks about how the index fund and friends has warped the benefits of ownership to leave companies effectively "unowned".
Most just are kind of "managed", especially after a "star CEO" or similar moves on.
Some companies in Europe have what might be part of the solution, with the union et al having board representation.
This can be true in VC-backed private companies too, but with public companies it seems to be even more amplified since the investors unlike angels/VCs often don't even know let alone care what the company really does.
Good on tailscale for fostering the community and not playing this like most startups would!
I have this pattern where i avoid software i can't self host, because while i love paying for my products - i don't want to be cloud trapped. So some software/hardware, say Ubiquiti's suite - i buy and run locally. But sometimes cloud features are nice, so i enable them.
I don't _want_ Cloud, but knowing i'm not trapped makes me far more likely to be a customer. Knowing i can opt-in to cloud, opt back out, etc is great.
In practice i often end up buying Cloud. But i only first bought and continue to pay for services when i know i'm not trapped. The moment they start to make self-hosting a pain, or inhibited - i'm out.
Of the four (1) is the least shady.
From a security perspective, I would design this feature differently. If the capability to change the control server exists, then, rather than hiding it, I would want to see a prominent UI element displaying the control server name, url and "more details" to the user to see before they connect/login.
This is important to prevent any social engineering based security hacks.
The whole Tailscale experience for an enduser (ie not Tailscale admin) is so much nicer than compared with something like OpenVPN in a place without MDM.
to be fair, their mobile UX has plenty of warts and behaviors that don't match platform expectations and are confusing (like what happens when you tap on any of the listed machines that you have access to).
This one seems to at least have been partially motivated by making sure that accessing tailscale without paying is not too visible.
I'm saying this as a huge fan (and paying customer) of tailscale.
Not sure what this means, Tailscale is free for the vast majority of non-corporate users, and I would imagine that anyone who's using it so intensely that they need the "personal pro" plan is probably someone techie enough to dig around and find out about headscale.
Also headscale isn't entirely free if you're paying for a VPS or other server to host it on.
An extra field in an "Advanced Settings" menu should not need to be hidden behind some "Press About 5 times" secret gauntlet. Users are not so stupid that they will fill out an "Advanced" form field they don't understand, and even if they do, you can always make a connection attempt to see if the input was valid.
In what form? The private keys never leave the nodes, hence there shouldn't by any access per se (see https://tailscale.com/security/). Of course TS has insights into your networks, i.e. what servers it is installed on, what you connect to - so metadata.
But it still seems like they could flip that feature off if they got compromised. To remedy that, feels like they could support a preshared secret that they don't control / see being shared as a first step: https://tailscale.com/kb/1099/device-authorization/#generate...
Since Headscale exists, though, this problem is solved quite neatly.
Nothing in the Tailscale design has ever pointed to features that would guard your infrastructure from them.
I also believe that traffic inside homes should be secured regardless since routers can be hacked. So in my case, I didn't consider it a duplicated effort. I had my traffic already encrypted and authenticated when I started using Tailscale.
Maybe headscale could run at home, served over a tunnel[1] to a VPS. But honestly, if I ever lost confidence in the trustworthiness of Tailscale the company, I would just connect my devices with some other overlay network like Yggdrasil[2] or Tor.
[1]: https://github.com/anderspitman/awesome-tunneling [2]: https://yggdrasil-network.github.io/
It's a bit more involved than Tailscale with the benefit that it uses Vault's robust authentication options.
But honestly, headacale is better and more advanced than it.
I’ve been running my own Homebrewed WireGuard configuration mechanism for N=~10 machines using Ansible because I did not want to use a proprietary product. This gives me the confidence to eventually switch over to headscale.
I mean every feature and blog.
As a start up person, I am really curious about their marketing.
It seems to me like I would want two “users”, but that pushes me into their pro or business billing. Which tier should I go for?
I wonder if Headscale can also use internal credentials? As far as I remember with tailscale you had to log in with Google or Microsoft which is another total deal-breaker. But I haven't looked at it in ages as the hosted variety was a non starter anyway. Edit: Indeed they now have local logins, but still I would want to be the only one who controls access :)
I don't have a problem with paying for a good product, it's just the control that's an issue for me. For something as crucial to security as this, it needs to lie with me alone. Though I do prefer to just buy software outright instead of subscription models. Since I will do my own hosting, I don't think this is too much to ask. Perhaps they could offer a paid tier for people using headscale.
from the project page:
https://github.com/juanfont/headscale
>Node registration
> • Single-Sign-On (via Open ID Connect)
> • Pre authenticated key
why im still using keycloak
But nothing against keycloak - keycloak is the gold standard. But compared to Authelia, Keycloak is really cumbersome to get up and running and also to maintain.
I would need more security keys but it sounds like there is a non-gui method? That'd be fine for me.
What about iOS?
In general the OSS operating systems get OSS clients, whereas the closed-source ones don’t necessarily get the full OSS treatment.
That makes sense and seems like a legitimate line to draw. Being a little bit of a pain, I would point out that the Google Play store and Google's components for Android are not open source. If you're willing to make Tailscale available via Google Play, and open source the client, maybe iOS can as well? And while we're at it, macOS apps can be installed out of band of an app store, so maybe that can be open, too. It could even share a codebase these days.
As far as I can tell, the only Google Play Services API the app distributed on the Play Store uses is Google account authentication via the Play Services Google account picker.
For now, we've optimized for doing that for operating systems where users most expect it.
Mostly because developing for iOS and macOS is terrible, especially when your app needs to have "entitlements". Tailscale uses a "Network Extension entitlement" which is linked to our corporate Apple account. Even onboarding new employees and getting them up to speed on xcode/macOS/iOS development is painful. It often requires a bunch of messing around with Keychain and random reboots (not just Xcode restarts!) because something in the macOS kernel gets confused. For some development we also need to disable System Integrity Protection. And make sure there aren't duplicate copies of certain files between /Applications and ~/Library/Developer/whatever.
And then once you get it all working, some cert or login or something in Xcode or Keychain expires in a few months and you have to re-learn the whole esoteric dance once again.
The whole process of developing Network Extensions is pretty terrible.
Even if we open sourced it, you couldn't just git clone it & hit play in Xcode. Even if you paid Apple $100/year, you still couldn't, because your Apple account isn't blessed enough with the right to use a Network Extension.
It's hard enough for us to support Apple platform development internally without helping the world learn Xcode/code signing/entitlements/Keychain.
I've been and remain a huge open source fanboy for about 25 years now. If I thought we or the community would benefit from it being open source, I'd argue for us open sourcing it. But it just doesn't seem worthwhile. Or maybe I'm just still angry at the platform.
For what it's worth, my want is to use Tailscale (or similar) for a family setup, which ends up feeling like enterprise to me as a tech guy, but without the pricing of it. Things like SSO are big to me, but I can't justify paying enterprise pricing for it. If there was such a plan, I'd be your first customer.
It really does feel like Apple just doesn't care that their app policies are hostile to developers because they have such a strong monopoly on mobile app distribution.
I have dealt with mac/iOS network extension BS before too so I feel you there. But, on that front, it also means I’d know a bit about what’s going on and find the code insightful.
* NetBird (https://netbird.io/)
* Firezone (https://www.firezone.dev/)
No support for exit nodes for example, or DNS hostnames.
Compared to Tailscale the main weak point of these clones seems to be ACLs. Tailscale's system is very robust and surprisingly simple. The others I've seen are less well developed. I'm sure they will get there in time, but for now Tailscale is definitely the best if you want to control access.