Just use wireguard. It really isn't that hard.
Just use wireguard. It really isn't that hard.
The thing is, what makes tailscale works really well as a "central" control server is that it makes a lot easier to connect your personal machines. You don't need to deploy your own server, or mess with networking stuff. You just download it, log-in and there you go. I myself have invited some non-tech friends to my network for playing lan games from time time and they find pretty easy to setup tailscale on their side.
What may theoretically happen is that the same client won't be able to join both an open-source controller and a controller from Tailscale-turned-evil.
I suppose that corporations, especially those without huge IT departments, will and do happily pay Tailscale the reasonable money, and have their secure VPN just working. For them, it's no different than paying for Zoom or Office365, only cheaper. They totally do not want to depend on in-house networking expertise.
So I think Tailscale will be doing well financially,
For us. For the folks who browse HN all day, yeah. But have you tried getting a non-technologist to use it? I set a friend up with Tailscale between her Synology and laptop and it was a breeze - something I could do over the phone. For me getting Wireguard set up wasn't tricky, but I definitely leaned on Google some, and I would argue I know what I'm doing.
I would love for a company to release bridge as open source that I could deploy on a VM somewhere but still have it be Tailscale easy for normal folks, but there's no money in that model.
Further, Honestly at this point I would trust TailScale over say OpenVPN, or Cisco, or .....
Road 1: Sale to usual suspects like Palo Alto (though that window is closing due to raising $100M) or Cisco (that window may close if they raise again?). It is basically modern vpn, though will be years with a big enterprise culture reset & a consumer tier for that to become true. They will run out of acquirers soon who would have the incentive to overpay, eg, if they raise more and narrows down to say oracle, ms, apple, and google, not sure why any would buy vs build. Hopefully they will not dip much into the funds so they can cleanly exit without forcing an acquirer to screw over their users. (See: Evernote)
Road 2: IPO and become a platform for bigger stuff... Like end-user-friendly VPN. Who knows, but good luck! Flipping to 'real' enterprise sales and figuring out the consumer tiers are big culture shifts, but luckily... Hireable.
Meanwhile, growing just with more niche/skilled Linux power user teams gets them far -- the compliance checkbox is huge for growth, see Drata and Vanta -- so am not worried :)
Agreed with the OSS concern so we decided against putting them in the critical path of our enterprise offering (a shame!), but as an internal tool, it looks great!
In many situations it's not just hard, it's outright impossible.
For example, how would you connect two Raspberry Pis between two CG-NATted internet connections using Wireguard, without resorting to setting up a publicly reachable VPN server?
If you have a public and at least semi-stable IPv4 address and control your firewall/NAT, great. But unfortunately less and less people do, these days.
Have you tried using IPv6 on a hotel wi-fi, in-flight, or a corporate guest network?
TLDR; Ideally, IPv6. Otherwise, NAT traversal techniques such as STUN, or hole-punching.
Yes, if you have it everywhere you want to host services and everywhere you want to access these services, that's great. Realistically, I think it's going to be decades until an IPv6-only service is feasible.
> Otherwise, NAT traversal techniques such as STUN, or hole-punching.
Neither of which Wireguard supports out of the box. To be clear, it absolutely shouldn't – it's a different concern, and the appeal of Wireguard is specifically that it isn't trying to do everything and the kitchen sink.
So, is there an easy-to-use NAT traversal orchestration service for Wireguard out there that isn't Tailscale?
So, before Tailscale there wasn't a solution. Now we have one, but it's yet another tool we have to manually manage.
I love WG and use it extensively, but the attraction of Tailscale (and why I use it) is that it takes disparate concepts and gives you a nice visual control panel to manage them and see the status of all your devices in one place.
Nothing. Absolutely nothing exists for Wireguard that does even some of that, which doesn't also cost money.
I don't think Wireguard is even capable of the 'DERP' server concept to get around NAT limitations.
So no, you can't 'just use Wireguard' to accomplish what Tailscale does.
I can't (and refuse) to live my lie by "what ifs." If they do any of those things, it's easy enough to pivot to the 3 or 4 other providers our there, like ZeroTier, who offer the same thing.
My hope is if they do, the FOSS community will have gotten their act together and built a capable replacement, which is usually the case.
- locking the software behind a paywall
- locking the software behind a paywall
- inventing a proprietary + open-source + pay us royalties license
- pretending that their software is free whilst employing a proprietary + pay us royalties for anything bigger than a hobby project license
- going bust