11 ms·
Tailscale has reached general availability
- kaffee 7y agoSeems like it requires a Google or Microsoft account (or corporate SAML). No thanks!
- bsg75 7y agoI expect their target audience (for revenue) are companies who need corporate SSO support.
- apenwarr 7y ago(I'm a Tailscale co-founder) The idea is to avoid building yet another commercial service that holds onto your username and password. People have enough identities already. More details here: https://tailscale.com/blog/how-tailscale-works/ https://tailscale.com/blog/how-tailscale-works/ We know we keep getting feedback that people want a different way to authorize their accounts (especially for personal use), so we're looking at other options. We just really want to stay out of the username+password business; it's simply bad security practice.
- mromanuk 7y agoMaybe you can look at Sign In with Apple, it works native and for websites too. https://developer.apple.com/sign-in-with-apple/ https://developer.apple.com/sign-in-with-apple/
- CharlesW 7y agoThis, please! I'd personally prefer username/password auth, otherwise I believe that this is the most privacy-focused option. https://support.apple.com/en-us/HT210699 https://support.apple.com/en-us/HT210699
- apenwarr 7y agoI really love the privacy- and security-centric design of Sign In with Apple, but so far it only works if you have Apple hardware, right? Tailscale's selling point is you can use it on all your devices (modulo Android support which isn't released yet).
- bgentry 7y agoQuoting from the page linked above: Sign in with Apple works natively on iOS, macOS, tvOS, and watchOS. And it works in any browser, which means you can deploy it on your website and in versions of your apps running on other platforms. So it at least sounds like it can be used anywhere with a web login flow. Although the docs say this must be accomplished using their JS library, as opposed to a standard OAuth2 flow of some kind: https://developer.apple.com/documentation/sign_in_with_apple https://developer.apple.com/documentation/sign_in_with_apple
- apenwarr 7y agoCool! Maybe it's more doable than we thought.
- enos_feedler 7y agoFWIW I setup tailscale a few days ago with an iPad mini, iPhone, and Mac mini server. I don't know how many networks would be "Apple Only", but I would certainly prefer a quick Apple Sign in button vs. using Google.
- c17r 7y agoSince it's mostly tech-savvy people here that want something else and I'm assuming it's an oauth process, perhaps github and/or gitlab?
- dave_universetf 7y agoGithub's on the list to support, yeah. We can speak most "identity provider" protocols these days (OAuth, OIDC, SAML, etc.), but it's this weird little universe: the protocols are meant to let you implement once to support everyone, but in practice every IdP has its own little idiosyncrasies that mean you need a little bit of dedicated code for each new IdP. So, we end up with a backlog of "support IdP X, which is ostensibly OAuth but does something strange we've never seen yet" :)
- c17r 7y agoThank you for your response. Having battle scars from handling authentication in an enterprise SaaS, you'll notice I chose my words carefully and didn't say "just do/use" :) I really want to give you guys money for my personal use but $10/user/month is steep when I know the other users will only use it once it a blue moon (but of course, when they need it they'll REALLY need it). If there was something like a "supporter plan" that was similar if not identical to the free plan but charged a flat fee, I'd be all over that.
- dave_universetf 7y ago"supporter tier" is an interesting idea! We're still figuring out what kind of pricing makes sense for personal use vs. company use. Hopefully we'll have something soon! In the meantime, it's fine to be on the solo plan for personal use, it's there and free to be used :)
- deleted 7y ago[deleted]
- mholt 7y agoI'd actually rather you have my username and password, since I use a password manager and every password is long and unique. I don't want to tie my Google/Apple/<X-Mega-Corp> account to my Tailscale account. This way I can also more easily keep track of which accounts I have since my password manager stores them all. So I will wait for email signup (which currently just subscribes me to a mailing list...)!
- bradfitz 7y ago(also Tailscale) FWIW, we'll probably also be supporting GitHub (and maybe Twitter?) auth, as well as perhaps letting you run your own auth server if you set up the right DNS records. Lot of things yet to do.
- dstaley 7y agoSuper excited to see that you'll be supporting GitHub! That being said, do you have plans to implement any sort of account merging? For example, the ability to login with one of multiple authorized accounts (so my Google Account, my Twitter account, or my GitHub account).
- apenwarr 7y ago(Tailscale co-founder) This question goes through my mind a lot. I personally want it for myself. However there's a "weakest link" problem in identity management: if you have N identity managers merged together, then your account is only as secure as the weakest one of them. So connecting multiple identity providers to one account might be risky. On the other hand, I really like Keybase's way of federating multiple identities together, where each additional identity provider increases rather than decreases confidence.
- philsnow 7y agoThere's more than just security concerns, when you allow a bunch of third-party accounts to access one of your first-party accounts. If your highest concept of identity is the account and identity managers allow you to authenticate to that account, let's say you have a tailscale account with id 123, and any human who has access to john@personal.org or john.smith@job.com can access that account. What do you do when John leaves job.com? Can John (accessing the account through john@personal.org) still admin the job.com bits? I think the right abstraction is having first-party (in this case tailscale) accounts belonging to one or more "teams" and authenticating with a @job.com address allows you to switch to the job.com team in the UI / allows you to generate API creds that modify job.com's team.
- ahnick 7y agoHave you considered integrating with Keybase? I think the identity system of Keybase coupled with the secure mesh networking of Tailscale would be a really powerful combination.
- apenwarr 7y agoI quite like Keybase. Do they offer an oauth2 or SAML login feature nowadays that somehow integrates with your strong device authentication?
- bradfitz 7y agoI just started talking to Max at Keybase about this today, actually. It'll require work on both our sides, but we both want to do it.
- ThePowerOfFuet 7y agoSo why not Webauthn?
- api 7y agoWe (ZeroTier) dragged our feet on this stuff for a long time because we are personally of your mindset, but we get asked for it a lot so more of it will be coming. The ability to use your own auth and your own other things will never go away though, and with ZT you can run a fully independent network controller if you want. Personally I want ZT to integrate support for integrated (e.g. Apple security chip) and discrete (YubiKey etc.) secure tokens and enclaves. That is where the real security is at.
- yingw787 7y agoVery nice! Congratulations on launching, and looking forward to seeing your success in the coming years!
- royjacobs 7y agoLooks really interesting! For my use case I'd really want that Android app, but other than that this looks solid.
- armaxt 7y agoI will get banned for this in a matter of minutes but I will say the truth to whoever think HN is fair. For the past 3 months, every, again EVERY post that was linked to Tailscale (not just the company domain but also the blog posts of the founders' websites), has gotten to the frontpage within minutes, with a full 100% hit rate. This cannot happen for any company, any project or anything else to be honest since there is a thread that gets posted every minute on average, and almost every thread, no matter how great it is, goes forgotten forever without a single upvote. This doesn't happen to even trillion dollar companies that are known by almost everybody so certainly this can't happen for a company of 5 people that was started only last year and hardly known by anybody. Nothing can get to HN's frontpage at a hit rate of 100% especially when you know this has been happening on almost a weekly basis since last December not to mention the daily promotion in comments on literally everything that has anything to do with WireGuard or even VPNs. HN simply favors some founders who have good network over the rest of us. I know that organized upovting and astroturfing isn't uncommon here, but there has never been anything anywhere near that's being done by this company and its founders here. This is simply free advertising worth of hundreds of thousands of dollars for free simply because the founders "know people". EDIT: Thank you HN for proving me right! This comment has 42 points as of now and it's buried in the bottom below almost every other comment. Still not a response from the founders who very coincidentally happen to exist literally during every time a post about their company gets submitted!
- BooneJS 7y agoWell, and whenever Google sunsets a product.
- cbg0 7y agoHaving your friends upvote your posts on HN doesn't mean HN "favors" you.
- deleted 7y ago[deleted]
- toomuchtodo 7y ago> Can I ask people to upvote my submission? [1] > No. Users should vote for a story because they personally find it intellectually interesting, not because someone has content to promote. HN's software penalizes submissions, accounts, and sites that break this rule, so please don't. "A "voting ring" is when people get friends to upvote their stuff. This is against the rules. We want stories to be on HN because they're good, not because they were promoted." [2] [1] https://news.ycombinator.com/newsfaq.html https://news.ycombinator.com/newsfaq.html [2] https://news.ycombinator.com/item?id=7543910 https://news.ycombinator.com/item?id=7543910
- nubela 7y agoIs talescale really that popular? Who are upvoting these articles?
- dang 7y agoLegitimate, longstanding HN users are upvoting these articles, so as far as I can tell the answer to your question is a simple yes. More here: https://news.ycombinator.com/item?id=22762894 https://news.ycombinator.com/item?id=22762894
- microtherion 7y agoI can only speak for myself: I was interested in WireGuard for a while, but setting it up properly seemed rather a daunting task to me. With Tailscale, this was literally a matter of minutes. I'm not sure I would pay $10/month for this, but the free solo plan is sufficient for my purposes and works great.
- steeve 7y agoBeen using it for the last few months and it's great. I use it for SSH, NAS etc... Also, being able to ping my iOS phone that's on 4G from my computer feels like magic.
- ASalazarMX 7y ago> Also, being able to ping my iOS phone that's on 4G from my computer feels like magic. So, like every other VPN?
- steeve 7y agoTailScale is to other VPNs what Docker was to LXC. Well, except Hamachi.
- 3xblah 7y ago"Well, except Hamachi." As well as the one from the author of ntop. A few characteristics most projects consistently fail to meet are (a) keeping the source code available, small, relatively simple and easy to compile, (b) allowing peers the option to connect directly after discovery without routing traffic through a third party and (c) recognising that not all peers want to form massive infinitely scalable networks, most will prefer small ones. Most P2P projects choose a design that forces the majority of users compromise in order to accomodate a few unpredictable/hypothetical edge cases. "Perfect" gets in the way of progress. History shows there is no "perfect" when it comes to P2P.
- reinhardt1053 7y agoWhy my team should pay Tailscale 10 dollars/user/month? We can get the same features with Wireguard/OpenVPN.
- jasonvorhe 7y agoIf you can, do so. This reminds me of claiming to be able to build Dropbox in a weekend with existing tools. You can, but it most likely won't work as well, won't be as integrated and well, you'll have to build it yourself which won't be as easy as you think it is, then add monitoring and paging and, depending on your requirements, high availability. I'd certainly be interested in a blog post about this, if it's as easy. But considering that Tailscale took this long to launch, I have doubts that this is as easy to build.
- dfcarney 7y ago(Co-founder of Tailscale here) To that end, we started publishing a "blueprint" for people who want to DIY. There's more to explain (and questions encouraged). Please check it out: https://tailscale.com/blog/how-tailscale-works/ https://tailscale.com/blog/how-tailscale-works/
- zackmorris 7y agoThanks for this. From the link: My teammate Dave Anderson is writing a post about all the insanity that is NAT traversal. That alone will probably be as long as this entire article. Stay tuned! I've watched countless p2p projects fail due to NAT difficulties, and spent months/years banging my head against it only to fail too. I've heard that NAT is tragically still a thing with IPv6 as well. Please, if you all make it big, start a cross-platform open source, drop-in library that completely solves the NAT problem. The unit test for it would be that an app using it can accept inbound connections with zero configuration. That might require a central server though. I think the crux of the problem is how to share IP addresses with each other through that central server securely for STUN/ICE so that nobody can eavesdrop. Would you consider making your DERP servers free and open for that purpose? Apologies if I'm glossing over this or missed something, this is just something that has vexed me for almost 20 years. Thanks!
- sho 7y agoI've said this before - I really love the concept but I can't get past the pricing. I don't think I'm cheap, but I work in a startup and have to justify what I spend, and USD$10/user/month is very steep for the hard-to-explain benefit of doing away with jump servers. I already use Wireguard, I have a script to add users, update configs and bounce the servers.. it's not as cool and automatic and "zero trust" but it also doesn't cost hundreds of dollars per month to access my own servers I'm already paying for! GSuite is easy to justify for me. Github is. JIRA is. Tailscale is more expensive than all of them and it's hard for me to make the case, even to myself, that it's worth it. I'd like to ask Tailscale to think about alternative pricing models of maybe $20/month per admin account, which comes with 10 bundled "member" accounts or similar. That would get me to $40 or $60 a month, which I can stomach. But I won't pay $300+/month to save myself a little bit of inconvenience every few weeks so my devs can securely log into our servers.
- dfcarney 7y ago(Tailscale co-founder here). I certainly appreciate the feedback and suggestions. We've had pricing inquiries from individuals all the way to enterprise. Finding the right set of features at the right price is something we're going to spend a lot of time exploring (for instance, some larger companies don't care too much about ACLs, but some smaller ones really, really do). Right now, all I can say for certain is that our pricing page will change and that we're open to discussion. I'd love to hear more of your thoughts on where you think we can add value and what it might be worth to you. If you're up for it, please email me at dfcarney@tailscale.com Regardless, thanks again for the input.
- cpr 7y agoYes, at $10/mo as the GP says, it's more than Slack or G-Suite or Microsoft 365(?). It sounds like a great product, but it would definitely have less value to us than the above products. That seems to set a price ceiling, but of course, you're free to find the price elasticity curve by exploration...
- vkaku 7y agoI signed up for it, I got 4320 hours left ... What's to complain about it? Honestly, the customer in mind is not the startup with bootstrapped money. $10 a month is what people pay for a Netflix subscription, but this stuff is quite valuable. I think they may offer special plans for the poor, ailing startups but I don't see ANY reason to complain about their service.
- sbaha88 7y agoSorry for off-topic, but does anyone know which css library Tailscale used for their blog? Looks very nice and clean.
- blueside 7y agotruly a lost opportunity that it wasn't tailwind
- rosszurowski 7y ago(Designer behind the Tailscale blog here) Glad you like it! The text styles are custom, and the layout is built using an in-house CSS framework not unlike Tailwind [1]. But if you'd like to build something similar, you could get pretty close by using something like Tailwind and building with Rasmus Andersson's lovely (and open-source!) Inter type family [2], which we use throughout the site. [1] https://tailwindcss.com/ https://tailwindcss.com/ [2] https://rsms.me/inter/ https://rsms.me/inter/
- sbaha88 7y agoHi, thanks for your reply and great work:). The site looks just amazing and very clean (especially typography). I noticed it uses utility classes like tailwindcss so thought maybe there is a similar library.
- lwhsiao 7y agoCan someone comment on the tradeoffs between Tailscale and ZeroTier?
- jedieaston 7y agoI don't know if it's really ready without what they're calling "magic DNS": https://tailscale.com/kb/1054/dns https://tailscale.com/kb/1054/dns Something that bugs me about ZeroTier is also present here, which is that there's no name management whatsoever, so I have to either keep a hosts file around with all the names of the network or find a script on GitHub that does it for me (or put a DNS server on the Tailscale network, and make sure all the hosts have records on there manually since there isn't a way to automatically integrate it with the hostnames that Tailscale already logs). Or, of course, use public records and pray you don't have more than a couple services because who wants to log in to the domain host every time you bring up a new container? Half the magic of BeyondCorp (which I'm a big believer in) is that it's invisible from an end user perspective. I open a browser, go to git.corp.planeteaston.com, and it works, not "let's go to gitlab... it didn't resolve. what was the IP address again? 192.168.10-oh, wait, I'm offsite, the address is different, let's go see what it is in the Tailscale console", and a tech person could figure that out, maybe, never mind a computer-illiterate person in another department that was just told "go home, coronavirus, take your laptop". This isn't a knock, since the main competitor, ZeroTier, doesn't have a great solution for DNS either besides run a DNS server, but whoever cracks it will probably win this race. And it's almost worse for ZeroTier, which by default (at least when I started using it 2-ish years ago), wanted you to use IPv6 addresses by default that there was no chance of you memorizing. I'll be a customer when this works!
- TechBro8615 7y agoIndeed, my only problem with ZeroTier is that I cannot setup custom DNS routing on it. Currently I use nextdns.io on my phone to rewrite `www.mycompany.test` to the WiFi address of my laptop (I use https in local dev). I want to do this over mobile too, which would work with ZeroTier, except for the fact that I can't run two VPNs at once (nextdns + zerotier) on the phone.
- api 7y agoZeroTier has punted on this problem for ages because it's extremely hairy with a very long tail of edge cases and a lot of weird configurations in enterprises that we do not want to break. We really hate breaking stuff on user machines, and we also want to avoid pulling a Zoom and being more invasive on install than users expect. Then you have captive portal logins, people running stuff like Cloudflare's local DNS daemon or local dnsmasq, and more. It's the shaggiest yak ever so we have to make sure we have a really heavy duty shaver ready. We are working on it as soon as we ship 2.0, which is a huge undertaking that's taking longer than we hoped. 2.0 has a ton of important improvements including but not limited to professionally audited design and code (not revealing the security firm yet but they are extremely well known). Just finished our first round with them. (Bonus: our existing design is not bad and it won't take much to harden it a lot more.)
- brunoqc 7y agoCan you use tailscale with friends or does it only work with the same email address?
- dave_universetf 7y ago(Tailscale employee here) For personal use, we're planning a "sharing" feature, so that you can share machines (or individual services) with friends, and they just show up on their network (after mutual approval, of course). It's a feature I very much want for my personal use of tailscale, so it's going to happen :)
- brunoqc 7y agoThat sounds awesome. Thanks!
- dfcarney 7y ago(Co-founder here). If you're referring to the free tier, it only supports a single email address at the moment. What some people have been doing is to create a fake Gmail address and sharing that with their family/friends to use as a common login. We've been exploring the idea for a free (or significantly discounted) "family" plan (or even something like that for small teams). Please stay tuned over the coming weeks for some updates to our pricing and tiers.
- brunoqc 7y agothanks!
- mleonhard 7y agoDo you plan to release a Terraform provider for configuring Tailscale?
- dave_universetf 7y ago(Tailscale employee here) Automatic provisioning is definitely on the list. It's an enabler for immutable infra deployment, getting connectivity into containers, and building things like automatic enrollment based on external sources of trust (e.g. "automatically enroll any VM that can prove via its vTPM that it's in this GCP account").
- bawana 7y agoIf a site within a tail scale net is compromised, does that make all of the other sites instantly compromised on that net?
- e12e 7y agoCongratulations on launch! The solo tier looks very nice and useful (except for missing Android client for now). Low the sign-up flow, very easy. This looks very similar to ZeroTier - apart from building on wireguard - how do the solutions differ? Is tailscale also a true mesh (ie packets go direct between two tailscale nodes on a lan)?
- nodesocket 7y agoIn the dashboard, there is no link to support. There should also be a way to create a support ticket or even better live chat. I am getting intermittent errors in the dashboard as well.
- crawshaw 7y agoI've filed an issue for me to add a support email link. Will do another dashboard release in a couple days, thanks. As for alternatives, we tried chat but no-one used it, and it added a ton of heavy awful javascript to our website. You can file issues on https://github.com/tailscale/tailscale https://github.com/tailscale/tailscale, though for the dashboard I'll move them elsewhere. Also we have been looking at various pieces of "forum" software too but haven't settled on anything we really like. Could you elaborate on the errors you saw? If you want to send support@ an email with your account email address and rough time, I can look in the server error logs and try to hunt it down. Thanks. (I work on Tailscale.)
- nodesocket 7y agoThanks so much for the reply. I am sending an e-mail to @support now.
- nojvek 7y agoFrom the website > We’re announcing our public launch today, with a $3M seed round → Seed rounds are now 3M, wow! I wonder how they seemlessly authenticate with Okta, Google, Active Directory e.t.c ?
- sbr464 7y agoIs there a pfsense integration?
- sbr464 7y agoNice service, was just testing it out. I had one question/issue. Will the pings heal automatically if a device changes internet connections or wifi providers? I noticed I had to disable and re-enable the active toggle on an ipad after changing wifi networks (local wifi to phone/LTE). I didn't have to if simply disconnecting/reconnecting to the same wifi network.
- zhaoweny 7y agoAccording to the blog[1], Tailscale currently have a relay network for relaying traffic when NAT traversal does not work. I wish one day Tailscale allows private relay server, for privacy and speed / latency reasons. [1]: https://tailscale.com/blog/how-tailscale-works/ https://tailscale.com/blog/how-tailscale-works/
- dave_universetf 7y agoIt's planned. Although note that DERP only relays the encrypted wireguard packets. All we see is "please send this ciphertext blob to pubkey X", i.e. exactly what any router on the internet sees. Still, for latency and compliance reasons, it makes sense to allow companies to operate their own DERP relays, if they want to.
- j88439h84 7y agoIn "The asymmetry of internet identity" you're describing a problem and currently Tailscale doesn't solve it -- it relies on google/ms/etc for identity. I'm curious if it'd be possible to avoid using brands by just authorizing device ids like Syncthing does, without any login at all.
- RabbitmqGuy 7y agoHow about we add another pricing plan. It's for people who like me are happy with the free plan, but still want to somehow give you money without upgrading to the $10/user plan. Bonus points if you call the plan, the wireguard plan; and 90% of the payments go to Jason Donenfeld.