Apple TV, now with more Tailscale
tailscale.com
tailscale.com
Pretty huge. Many non-techy users don't like the idea of keeping a computer on 24/7, but a smart TV is just fine.
Also, the Apple TV 4k only draws 0.5 watts at idle and less than 3 watts when streaming movies[0], so I imagine it pulls less than 1 just tunnelling traffic. Computers pull 15W+ at idle, and that's with low end components.
0: https://www.apple.com/environment/pdf/products/appletv/Apple...
Linus Tech Tips has a video about it: https://www.youtube.com/watch?v=1vpepaQ-VQQ&themeRefresh=1
At $200, it was 4x the price, though.
My friends have Apple TVs that don't stutter, for 3+ years.
It may just be a problem for me, but as i have ~3TB of photos in iCloud (2 x 2TB), and unless i want to buy laptops with 2TB storage, there is no practical way of backing up the contents of iCloud, so i use a Mac Mini M1 with an external drive, syncrhonize data locally, and then back it up from there.
Do you use any special tools?
It does require each user to login again every time the mac mini is rebooted, but fortunately that only happens when new releases come around, so 3-4 times every year.
I do periodically check if new photos have been downloaded. I care less about documents as the relevant documents are more likely to also be stored on the laptops, and thus backed up through the normal backup routine on the laptops.
I do wish Apple would come up with a solution to this problem though. The official instructions[1] feels like something from 2003.
That wish is in the opposite direction of Apple’s brand identity: “let us handle everything for you with our white glove service [you can pay, right?]”
Pretty much everybody agrees that you need to backup your cloud storage as well as your local computer, and Apple even backs up your i-devices to the cloud, and yet, there is no automated way of backing up your iCloud storage.
About a decade ago, Google initiated the Data Transfer Framework[1] that allows you to transfer data from one cloud provider to another, directly from provider to provider instead of downloading it first. It sadly appears to not have gotten enough traction to be of any use.
I don’t think I’ve ever seen Apple say that you need to back up your Apple Cloud data.
> I would argue that it is exactly in line with Apple's brand identity.
I’m not following you. Can you explain what you mean by that?
Usually when Apple does something, they make it so it "just works" and usually stays out of the way of the user. To bake iCloud backups into Time Machine would do just that, backup your cloud data without bugging you.
But of course this is a different use case and not always an option. Not if you want to use Tailscale. Probably unless that Apple TV is already connected to one of this “VPN WiFi” with Tailscale on top (no idea what the functionality or performance impact is).
Anyone using glinet routers for that purposes and have any tips?
The Mango I have is on the slow side, specs say max 45Mbps over WG as a client, and I measured ~25Mbps when using a Mango as the server. But it’s tiny and very low power so perfect for travel.
No tips, it just works, but test it out before you leave for your trip!
Why would a non-techy user want to volunteer to be an exit node?
The terms "VPN gateway" or "VPN server" are still valid and less easily confused with Tor's use of "exit node".
In a tailscale setup, an "exit node" has specific meaning and the term makes sense as far as I'm concerned:
This potentially would be even easier for me, given they all have Apple TVs already. This isn't a public exit node - it's only available to other users (i.e. people you know and have granted access to) of your own TailScale setup.
Same for non-techy folks who have second homes in foreign countries, or even just travel a lot - an Apple TV running this new app back in their main property will allow them for free to browse the web as if they are actually at their main property, including any TV services they enjoy.
My Apple TV constantly goes to sleep.
Is Tailscale doing some type of “busy wait” to prevent tvOS from going to sleep?
No mention of how much they live trust and privacy or how they’re going to make your experience more delightful.
Why would someone want a VPN? There are a bunch, but here are some examples:
1) You want to connect to one of your machines at home while you’re at a coffee shop, or on vacation. Maybe so you can check security cameras, I dunno.
2) You’re on vacation outside of your home country, and you would like to watch a video stream that is blocked in the country you’re vacationing in. I experienced this in the Bahamas — If I recall, I was wanting to watch a UFC fight, but the UFC app refused to stream to the Bahamas (it was this and/or other Disney/Hulu whatever services refusing to play in the Bahamas). By routing traffic through your ISP back home: problem solved. (This what “exit node” is referring to — a computer through which internet traffic flows on your behalf)
3) You want to play a game with a friend that only supports multiplayer play on the same network, but your friend isn’t physically there with you in the same house. So just put the two of you on the same virtual network and now you can play together.
[1] In some cases this is not possible and there are relays setup to help route traffic. What's in the traffic is opaque to these nodes. You can also choose to use your own nodes. If you are interested here is a great post on how this works: https://tailscale.com/blog/how-nat-traversal-works/
Some VPN vendors bypass that by reselling access to residential IPs (witting or unwitting on the side of the person paying for the ISP service), but even that is hit and miss.
> Why should get another piece of hardware
Many people already have an Apple TV or Android TV streaming box.
> That’s why I think it’s not a great press release.
Press release? This a blog. It should be self evident that this is for customers and other already interested parties.
When you visit friends and family, do you regularly reintroduce yourself? I’m going to guess you probably don’t. If someone did that, it would both be weird and wasteful of everyone’s time.
Blogs work similarly. The majority of traffic is expected to be people already following you, in which case reiterating who you are, what you do, etc, would all be a waste of everyone’s time — with the minor exception of the occasional person that stumbles upon your blog for the first time. Even then, such individuals usually end up on an unfamiliar blog because they are explicitly searching for something topically relevant, and thus are already familiar with what is being described.
It’s kind of bizarre, IMO, to arbitrarily follow links from a link aggregator (Hacker News, in this case), with no prior knowledge of the related topic, skim through a blog on said unfamiliar topic, and then complain that the author didn’t spell out what 99% of their readership already knows. Like… why? If you like exploring things you don’t know, why not check out their homepage? You already clicked one link without knowing what you were getting into, what’s one more click to go to the very page that describes what they do? Or if you don’t like discovering new things, what compelled you to click a link, when the link text was completely foreign to you?
Car maintenance books don’t describe the usefulness of cars.
Calculus books don’t assume you have zero familiarity with numbers and counting.
Recipe books don’t remind you that, as a human being, you need food to survive.
The Netflix tech blog doesn’t tell you what Netflix is, describe “streaming” in the abstract, nor explain what movies are and why people watch them.
How little familiarity would you recommend that Tailscale expect from the reader of their blogs? Should plumbers be able to understand what’s being talked about? If they should tell you that they are a VPN service, should they also describe what a computer network is, what you can do with a network, and why they’re useful? Do they need to describe what a computer is?
I just… I just don’t get it.
> I just… I just don’t get it.
…better luck next time.
It's important to point out here that, in addition to this, the free plan also lets you send invite links to specific devices, which other people can add on their own accounts. That way, nobody has to go for the (quite expensive and obviously company-focused) free plan, you can share your device with as many friends as you like, and you're not sharing anything else beyond that single device.
The Apple TV serves as a local gateway relaying all the commands to your local IoT devices.
On a side note, tailscale is lovely. I have nothing but good things to say about them.
(Yes, you can technically use an iPad as a hub if you are on the old Home architecture)
Apple killed Back to My Mac, which sounded a lot like Tailscale exit nodes: https://datatracker.ietf.org/doc/html/rfc6281
They do call this out towards the end.
Traveling without the Apple TV and the exit-node can be your Apple TV.
> With a Tailscale exit node, you’re in control and you get the internet connection you’re used to. This new feature could come in handy if you’re traveling with your Apple TV and want to access the same geo-restricted channels you can see from home.
It's also a way to proxy your connections through a device at home, of course. Whether the Apple TV is the client or the exit node.
I can now, move Tailscale off that server, and put it on my Apple TV to use as my network for my DNS server when I am away from the house.
Tailscale isn't particularly useful for acquiring the pirated media in the first place, of course.
Would you need to reconfigure plex to use the tailscale ip addresses and then the Apple TX Plex app will stream over that address?
I would assume with this announcement, you can keep Plex private to your Tailnet and an AppleTV also on the Tailnet could use it without any port fowarding.
1. https://forums.plex.tv/t/remote-access-using-tailscale-magic...
Ah. Now I get it.
I'm going to play around with this later in the week.
I'm a free-tier personal user, and a little too cheap to give a for-profit corp money when I don't need to just because "I REALLY like the product". If I use headscale does that just cause a headache for the team, or is it good because it reduces traffic to prod?
I'm to cheap to pay when I don't need to, but its such a great product (esp for free) that I'd gladly change how I use the product to be less expensive or problematic.
Also, is it in theory possible to use WebRTC to negotiate Wireguard connections and not use any control plane?
https://github.com/tailscale/libtailscale
> Also, is it in theory possible to use WebRTC to negotiate Wireguard connections and not use any control plane?
you can write code to do whatever you want I guess, but that's nothing to do with tailscale
i recently read this with mulvad too and feel stupid that I don't intuitively understand how it works, and what it does and why it's needed.
Tailscale makes this really easy, and fast.
WireGuard is an outstanding mechanism for building secure virtual private networks.
You can run WireGuard on a bunch of different machines (or virtual machines) spread all over the world and give them the ability to talk to each other as if they were on the same LAN, with every packet fully encrypted.
TailScale has productized this. They wrote software for a bunch of platforms that makes it trivial to connect those machines to your "tailnet" - effectively a WireGuard network which their software manages for you.
They tie this to SSO - so you can install their software on your phone and your home server, sign them both in using Google SSO or similar, and now they're able to talk to each other on a secure virtual network.
I suggest trying the TailScale setup process to really understand how good it is.
Tailscale on its own is a mesh network that allows your devices to communicate (in a VPN, technically, yes) between themselves.
If you have an exit node, then you can route your traffic to that exit node in the way most people think of a VPN.
It also has Mullvad integration, providing Mullvad servers as exit nodes.
If you use an exit node, then its functionally equivalent to a VPN with fancy features.
Seems like Tailscale is a very souped up VPN, though. You can add more nodes to the network easily, and even have multiple gateways to the Internet.
You're conflating two concepts.
An "oldschool" VPN connection (using e.g. IPSec) is something that allows your computer to remotely "join" a real, physical LAN. It's basically equivalent to running PPP over IP: your computer "dials up" a daemon running on a server somewhere; that daemon accepts a stream of raw packets from your computer's network stack; and then that daemon dumps those packets out through one of the server's NICs onto a local network segment — where those packets are then handled by the switch they run into as if your computer was directly plugged into that switch. So your computer can acquire an IP address for its VPN "bridge" interface via DHCP from the switch; can talk to other devices on that private network through the switch; can talk to the Internet via NAT through that switch; etc.
Tailscale, meanwhile, creates a software-defined virtual LAN on top of p2p mesh networking of the nodes. There's no actual network segment anywhere that your packets are being dumped out onto; the "switch" handling your packets is a shared distributed abstract-machine that's partly running on your Tailscale client, and partly running on the other nodes' Tailscale clients. That virtual LAN doesn't have a routing table + NAT on it to translate packets into Internet-bound packets. Nor does the LAN have the ability to host L2 services like DHCP. It's just a functional L3 simulation of an L1 network segment, not a faithful emulation of an L1 network segment.
Set the DNS server on your phone to a Pi running AdGuard Home and block all ads and trackers when on 5G, not just in the browser.
Travel abroad with your laptop and designate your computer at home as an exit node and now all the traffic on your laptop looks like it is coming from that country.
Those are just the use cases I am using personally.
It doesn't matter if I'm at home or anywhere else, if I have internet then that just works. I don't have to open a port on my router, configure DNS, or anything like that, I just install and run Tailscale.
Personally, I don't care about TV so I won't be using one anyway.
https://kimbroughski.medium.com/how-to-use-a-tailscale-vpn-t...
For the average, non-technical user, Apple TV as an exit node for other device while traveling is super cool.
But for someone who is out of the country for a duration, it's also super handy. Netflix knows all the popular VPN providers and ban hammers them on a regular basis. But being able to use my Apple TV to watch my normal Netflix (or whomever) from any other country... because they think I'm at home? Super win.
Unfortunately I can’t ping any hosts through it or make any connections. This is in contrast to my other exit node, which is a docker container running tailscaled with user networking. It continues to work just fine.
Any ideas?
Thanks.
I've already been using it in a very similar way on a Chromecast (the one running Android TV), which made me use my Apple TV less and less, to the point where I actually unplugged it. This might just be its ticket back to an HDMI port :)
Its got a long standing request to add split tunnelling [0] (a standard feature on pretty much every VPN client you'll come across). But it seems in the spirit of re-inventing existing networking technologies, Tailscale also decided to re-invent what a VPN client does.
This alone makes me give this otherwise wonderful project a pass despite all the deservingly good press it gets.
An AppleTV with an app like Infuse will flawlessly play back 4K HDR or Dolby Vision videos client side (no transcoding) as well as 7.1 lossless TrueHD audio. Unfortunately it wont do TrueHD Atmos.
LG TVs get slower and more ad- laden with each update.
Oh look all of those family Netflix devices are in one home again!