Tailnet Lock
tailscale.com
tailscale.com
This feature is a very good step forward in security. I will take a look and if the implementation is sound, I am going to use Tailscale (namely if the Tailscale is compromised, I will not be automatically compromised, unless I manually accept external public keys, or install a bad update).
The problem with malicious updates can be addressed by providing as easy way to check the code signature. With a standalone infrequently updated app such as an AppImage app, this can be easily done by verifying the GPG signature upon download.
Big tech surveillance orgs being the SSO is an SPoF for the administration of the network. For something as critical as L3, I can't accept that.
I just use Nebula instead. It doesn't have a spiffy web interface or ssh auth chrome bolted on, but it works great for my purposes and it doesn't involve Google or Microsoft at any point.
IdP trust is on the list. There are some "easy" things we can do that help on the surface but make life harder for users. And there are some not-so-easy things we are researching. I hope to have answers in 2023.
Is tailscale at this point in any way involved in headscale or contributing to it or are there plans to fork it to keep it maintained?
Asking out of curiosity.
Edit: some explanation here: https://tailscale.com/blog/opensource/
Plus there’s the added benefit to their paying customers to know that we have an out if needed. It reduces friction in starting to use the product.
It’s quite clever from Tailscale.
But goddamn if that spiffy web interface is not just the bees knees. I relented and put in a Google account that I don't use very often for identity--no idea if that makes it more or less like to be arbitrarily banned by Google--and accepted the fact that access to Tailscale wasn't so critical for me that I needed to be worried about it.
But in production, I totally get it. But I'd probably still just pay for Tailscale's SAML and use Okta or something...
https://tailscale.com/blog/community-github-pricing/
I have been using Tailscale since the beginning personally, and have been trying to sell it internally at work, and since we have a GitHub Community I have integrated various Tailscale machines into some of our playground environments for others to test out.
You are like, the dream of all B2B SaaS startups.
But also, Tailscale is great, fight the good fight.
This way, if you don't trust Tailscale to distribute these lock-controlling keys, you could run a different mechanism of your choosing that would effectively control what nodes are automatically admitted.
There were a few things going on with that issue you mentioned; one of them is the way the wrapper library was written, the other was with some stuff in the GUI client that was happening on a background goroutine but shouldn't have been. That should be fixed in the current stable release.
As for the Windows client in general, it is going to be receiving a lot of love over the next few months!
I'll have to check out the bug sometime, but it sounds like it's just bad luck with goroutine scheduling and the order things execute in, in a goroutine that isn't locked to a thread. I can see it going unnoticed on older versions of Go (especially prior to weirder things like usermode preemption.)
https://github.com/tailscale/tailscale/issues/4133
That said, I'm not near the computer where I have it occur right now to check.
wireguard is a linux-first solution and all of the windows stuff for it is subgrade, and probably will continue to be for awhile. Still selling plenty of anyconnect/globalprotect have a stranglehold on windowsland and probably will for a long time.
Historically you had enterprise-grade VPNs that cost a lot of money, or OpenVPN. Both ran over IPSec or SSL, and neither were super straightforward to config/maintain, nor were they particularly performant.
Then came wireguard, which is awesome, but wireguard is just a transport. It doesn't have all the UX niceties built on top of it, like registering clients or generating / distributing keys. Tailscale does a lot of that lifting for you, so you can easily and quickly get a working VPN, at a low cost, with good performance.
Personally I manage wireguard myself, but I also self-host my own VMs, storage server, applications, etc.
Tailscale is like taking your car in for an oil change instead of doing it yourself, plenty of people find that worth it.
Personally, I use it to connect my home devices as if they were always together on the same LAN, even when they're not. E.g. Raspberry Pi, home NAS, "home" server that's actually in a different physical location, etc. All accessible anywhere at any time, even (say) from my laptop in a moving vehicle, without connections dropping even when my IP changes. It really is like magic.
At work, we use it so that remote employees can access locally-hosted applications, office NAS, etc. ACLs make it easy to employ the principle of least privilege, so that having a route into the office LAN doesn't immediately mean any and every device is compromised.
We've been able to do this with existing VPNs for a long, long time, but tailscale is by far the most painless offering I've ever used and I migrated away from OpenVPN completely.
One of my use cases for Tailscale was connectivity between my primary NAS and an off-site NAS I use for backups. Being able to bring my NAS to the same site/network I had set-up the off-site NAS and just have things work over the LAN without reconfiguring anything was a wonderful surprise.
(Yes, I’m aware I could save some overhead by reconfiguring but looking at the network traffic monitor I was happy enough with the throughput I got though Tailscale’s LAN routing)
Without Tailscale I would need a way to publish my routers current WAN address somehow (probably with DDNS), create a port forward rule on my ISPs router/modem and then setup a VPN server to listen to those connections.
Not to mention that the current ISP doesn't even allow me to login to their modem and setup port forwarding.
- I have a SOHO setup at home: several PCs/ my work laptop, raspberry pi, synology and ubiquiti. It means I can access ubiquiti console and synology via network as opposed to be some janky proxy that those company's provide.
- taildrop is great for sending screenshots and files from my phone to (can't wait until they let me send URLs/links/txt like KDEConnect)
- I also have a raspberry pi setup in an ABNB in another country. When I'm traveling I can use my house as a proxy for US based services and the reverse is true - if I want my browsing to look like my IP address in another country I can.
- Running a Jupyterlab instance on my desktop PC (WSL) and use it through my laptop from anywhere. Can also be accessible through phone/tablet if needed
- Simple routing of other services my PC exposes (Jellyfin for now)
- Access dev services running on my laptop through my phone without checking IP all the time
- Good replacement for AirDrop using Taildrop file sharing. AirDrop errors out if I try to use it on a "public" network (ex: University Wi-Fi)
Managing personal devices.
One day I had to go to the office and only then did I notice my keepass hadn't synced in months. My home PC was sleeping so I SSH'd to my Openwrt box, got the MAC for my PC and used etherwake to start it. From there I used RDP to login and get an updated password. All from my phone.
Technologically, it's based on Wireguard. Wireguard is fast; really fast, especially compared to OpenVPN. Using cutting edge cryptography and a new UDP protocol, Wireguard connections feel roughly zero-overhead (they're not, of course.) Connections are peer-to-peer and you usually will get pretty close to the fastest reasonable route between any two devices, whether you're on LAN or overseas, whether there's a strong NAT in front or not.
They've also engineered a lot of things carefully, instead of just cobbling together existing end-user tools in Rube Goldberg arrangements. (Not saying there isn't use of existing code; there totally is. But it's all very nicely integrated from what I can see.) Doing things "the hard way" can lead to more complicated software, but the way they've architected things makes the possibilities for expanding the utility of Tailscale to be nearly limitless. It's also amazingly entertaining to read about. Seriously, just read about how their web browser SSH client works:
TailScale seems to have a better ui and more tooling (File sharing, SSH, ...). Even though those recently led to RCE[0]
I run it on every device I own, plus a few at my parents' place. This way I can access my PC and my NAS from my phone, and my NAS from my PC, even though the NAS is behind my home router and the PC and the phone can be connected to a bunch of different networks.
Tunneling compared to Dyn DNS at least has the advantage of more security via reduced access to ports. So maybe that alone is worth $5/m. .. well, $10/m, since i have two users. $10/m seems a bit steep just for some small access to my internal network for things like Camera Feeds, etc.
Dyn DNS + some safe self hosted VPN might be more affordable and just as safe compared to Tailscale.
.. thoughts on the best service to price ratio for my needs?
If the former, Tailscale isn't really a good fit since it only permits access to authenticated devices.
If the latter, Tailscale is perfect. It's a VPN in the original sense of the world, "private" being the operative term - your devices can communicate as if they were all on the same LAN, without worrying about their traffic being eavesdropped.
As for the pricing, I'm fairly confident that Tailscale won't mind if you're sharing a free plan (so single-user) across e.g. your laptop and your wife's, even though there are technically two "users" there. They've made it pretty clear that the divide they care about is "personal use free, company use paid."
Though i just noticed that the Personal Pro plan works with up to 100 devices for $4/m. Might give that a try. I really like paying.. as i hate free VC services.
edit: Wow, the signup requirement is bizarre though. I don't have or want Google or Microsoft.. i do have a Github, which i guess i'll have to use... but what the hell? So odd that i can't just signup with my email.
My guess is they will eventually add a sign-up-with-email option, but it's pretty far from the top of their priority list.
So i just signed up with an alternate Github "Identity" account to use with Tailscale. Still feels weird, but we'll see how it goes.
Personally I host both of these services (dynamic DNS client, wireguard server) right on my WAN edge router, but you could also run it on a host (e.g., VM or raspberry pi) inside the LAN.
While i like free (selfhosting), my gut says $5/m would be worth having Tailscale manage security for me to ensure it's done right.
As far as setting it up securely, I don't think you're any worse off doing it yourself compared to using tailscale. You can define what networks each client may access. Personally I run wireguard on top of OpnSense, so I also have firewall rules in place to limit what any client can do from my remote-access network towards other parts of my network.
Not if your IP is behind CGNAT or the like.
> $10/m seems a bit steep
They have a free multi-user plan but it's in small print on the pricing page and requires use of Github for user management.
That works if your IP is globally reachable.
> For basic tunneling into home servers, is Tailnet.. overkill
It's a service. You just pay money and they take care of it, instead of running this all by yourself.
> thoughts on the best service to price ratio for my needs?
You can buy VPS for $14/3m = $4.66/m and configure Headscale or whatever on it. Fixed public IP, no need for DynDNS, no user/$ limit except CPU/RAM - you can have whatever you want on it.
EDIT: found out they even have a $11/3m plan = $3.66/m.
Off the top of my head I'd do something dead simple like verify the user account matches our domain and then also query an inventory system to verify it is indeed a device we manage through MDM (though I'm not sure how this will work for mobile devices. We don't MDM those).
When a new device attempts to join you should have some data on it via the API (User, OS, Tailscale version, source IP, machine name). You could use that data to decide to endorse it or not.
If you're okay with trusting Tailscale's control plane, we have a feature for exactly this use case! Its called Device Authorization: https://tailscale.com/kb/1099/device-authorization/
You could also use tailnet lock in this fashion, by issuing a `tailscale lock sign` command for the new node once you've verified the provenance of the new device. Because it involves signatures with keys on your device it could never be as simple as a REST API, but maybe we could offer a more easy to automate command or better client library support (suggestions welcome!)
Thanks for the feedback!! Writing the documentation for how this worked was a challenge, and its good to hear what pieces we need to call out more strongly in the future.
If you're interested in gory details around tailnet lock internals, we have the beginnings of a whitepaper here: https://tailscale.com/kb/1230/tailnet-lock-whitepaper/
Ive heard a bit about tailscale networks connecting devices together easily. Is it for your own network only, or can other people access your tailscale devices directly as well?
Ie, I host a minecraft server on my linux desktop. Can tailscale help me in the use case of providing an IP to people to connect to it? Or am I just back to regular old port forwading and my external IP?
You can think of it as a LAN for all your devices regardless of what network they’re physically connected to.
The default use case of Tailscale is to have a private LAN, just for you, not your friends. This is changing now, though.
Tailscale does as of recently have the ability to do what you’re saying for Minecraft. It’s called Tailscale Funnel. This lets you expose a port on any of your devices to the public internet with a TLS enabled host name.
Another option for your Minecraft server is to use Cloudflare Tunnel. Works great for this kind of thing and is pretty much functionally equivalent to Tailscale Funnel.
I would like to just be able to send strangers a temporary permalink to my server for a one-off session, then turn it off or have it expire automatically once we're finished. This would not be feasible if I have to also ask whomever I come across to install clients, as opposed to just connecting from within the game.
To answer the question in another thread, node sharing also works with UDP. (Funnel is TCP-only due to the vagaries of IP addresses and TLS certificates when facing the outside world, sigh.)
I wonder if Tailscale is an acquisition target.
From a personal standpoint, I would like to see Cloudflare (among others) smashed into a neutral backbone provider and all its product offerings spun off, ala https://en.wikipedia.org/wiki/Breakup_of_the_Bell_System. It's dangerous for one company to control so much of the internet's infrastructure and it's causing massive problems (like https://news.ycombinator.com/item?id=32912075). Tailscale should remain independent.
I’ve emailed the mods tens of times over the years to point out a thread that has a correction, or that I think dang may want to reply to, without saying that I’ve done so. Did I do so this time? (Y/N)
Assigning meaning to the timing is inappropriate, as it disregards the possibility of coincidence (he found the thread organically), unstated actions (someone emailed the mods), and/or human distraction (he was at lunch) by the however-notified dang.
I also view it as impolite to try using @dang to burden all mod duties onto one person rather than to a team of mods. Whether it works or not, it’s evidence of site users setting dang up in their minds as a single point of failure – either because they think it’s the only way, or for the convenience of not having to write a two sentence email to the mod team. That irks me, and so I occasionally post a reminder about the contact form, phrased to allow for the cases where the @ is just a learned behavior and they just don’t know about the contact link in the footer yet.
They're not. It's just roughly when the post a new blog entry, which is... usually about once a week? Sometimes it's about new features, sometimes it's about internals which might be helpful for other people to know about (like the previous entry was about internals of the TUN/TAP, and how they managed to speed it up a bunch).
This article in particular is interesting because Tailscale inserting malicious nodes is the #1 concern I had around their product, and their solution (tailnet locks) is interesting and probably better than the solution I would have come up with (using Wireguard's support for additional symmetric secrets).
Finally I think it comes down to this: Tailscale is full of the same kind of people who tend to hang out on Hackernews. HN loves Tailscale because Tailscale is HN's ingroup.
Fly.io is in a similar situation, and similarly sees a higher-than-average fraction of their blog posts getting traction on HN.
For an interesting counterexample, look at warp.dev. They have a lot of the same markers - tackling an interesting problem that affects many HNers daily (the limitations of the terminal), building things from the ground up in Rust, and writing highly technical blog posts about it - but at the same time, it's clear that as an organization, they don't quite get it. They can't understand, for instance, why putting telemetry in their terminal emulator is absolute suicide as far as HN is concerned, or why "moving the terminal to the cloud" is a phrase that will never make HN happy. Unlike Tailscale and Fly, they are not "of the race that knows Joseph", as it were.
That's not to say that there aren't individuals at Warp who are members of the HN ingroup. But at the organizational level, Warp just isn't quite it.
I remember opening it, seeing a GitHub login page and instantly closing it.
It just seemed so tone deaf.
Also, they're just awesome folks!
Sometimes a BFD tech comes around. Even if it’s not immediately obvious, Tailscale is a BFD.
The blog and the website loads in so many trackers (reasonable, given metrics are important when you're busy hyperscaling a venture-backed startup), that folks at Tailscale should seriously reconsider positioning themselves as some paragons of privacy. No offence (:
https://news.ycombinator.com/item?id=25457440
> ...practice perfect anonymity to sell a product which does have security/privacy in mind?
So are free users "the product?" No. If we're going to fix the Internet, there's no point only fixing it for big companies who can pay a lot. That misses the point of the whole adventure. The Internet is for everyone. We have to fix it for everyone, or why bother? We knew we had to design a business model and a technical architecture that removes any incentive to abuse your privacy. - CEO at Tailscale, https://archive.is/R7jqw
Not on my browser. Maybe you should consider a better browser and/or install some extensions.