8 ms·
It's worth noting that the Tailscale client is, almost entirely, open source. It's just the iOS/macOS/Windows client code that's closed source (just GUI wrappin
by Operyl 4y ago
It's worth noting that the Tailscale client is, almost entirely, open source. It's just the iOS/macOS/Windows client code that's closed source (just GUI wrapping it), iirc[0]. The DERP code is also open source.
Additionally, there's an open source reimplementation of the control plane called headscale, as well. The Tailscale team has complimented it, but of course it's all on your own if you choose to run it.[1]
[0] https://github.com/tailscale/tailscale https://github.com/tailscale/tailscale
[1] https://github.com/juanfont/headscale https://github.com/juanfont/headscale
EDIT: Android code is actually entirely open, oops!
- ngcc_hk 4y agoWonder why those are closed source if just gui wrapping.
- sneak 4y agoWell, you can't sometimes or halfway be committed to software freedom, so it's because they only open sourced the other parts for marketing.
- Tostino 4y agoTo make it harder for a competitor to pop up and offer their own flavor of the binaries and support. It's just to raise the barrier of entry to others monetizing your project
- danielheath 4y agoMaybe because nobody on iOS/macOS/Windows cares if there's closed source code running on their machine.
- rollcat 4y agoI do, and wherever all other things are equal, I always choose an open source solution. But if all other things were always equal, I'd be running OpenBSD full time, so...
- cynix 4y agoBeing open source is not as useful on iOS though, since there’s no way to verify that what they uploaded to the App Store was actually built from the source that you can see.
- rollcat 4y agoHow often do you rebuild your system and verify all checksums? What's your threat model?
- cynix 4y agoThe point was that you _could_ verify whether a binary package matches the source if you wanted to on other platforms, not that you _have to_ do it all the time. With iOS you don’t have that ability so you’d have to have complete trust in the developers. The threat model is someone publishing innocent source code but sneaking in something malicious in the version they publish on the App Store, of course.
- rollcat 4y ago> The point was that you _could_ verify whether a binary package matches the source if you wanted to on other platforms [...]. Which platforms? From Debian wiki (https://wiki.debian.org/ReproducibleBuilds https://wiki.debian.org/ReproducibleBuilds): > Reproducible builds of Debian as a whole is still not a reality, though individual reproducible builds of packages are possible and being done. So while we are making very good progress, it is a stretch to say that Debian is reproducible. Apart from Debian and NixOS, I'm not aware of any other large-scale efforts to make builds reproducible, so this something you have to assess on a case-by-case basis for every single piece of software you might want to download and install. Not IF the checksums match, but IF the project aims for reproducible builds in the first place. By the way, if you download an iOS app on an M1 Mac, you can inspect its archive freely, including generating and comparing checksums of each file, disassembling the executable, and so on. So while not every iOS app can be downloaded on a Mac (the developer actually has to opt out), and not everyone has access to an M1 Mac, this is not entirely impossible. > With iOS you don’t have that ability so you’d have to have complete trust in the developers. This is not entirely true. I also have a certain degree of trust in the application sandbox provided by the OS, and in the app review process. I know neither is perfect but it's not like everything I install runs with full root. > The threat model is someone publishing innocent source code but sneaking in something malicious in the version they publish on the App Store, of course. What is your strategy for applications that do not publish any source code? Do you exclusively use software with source available? Don't get me wrong, you raise valid and important points, but this is a way bigger fish and "if only Apple did X" is just the first step.
- ignoramous 4y agoFor tailscale, I suspect open source is a way to market their software. I guess open sourcing iOS, macOS, Windows isn't worth the marketing advantage. https://apenwarr.ca/log/20211229 https://apenwarr.ca/log/20211229 (the gift of it's your problem now)
- cortesoft 4y agoSo they can make money?
- justsomehnguy 4y agoBecause if I need to deploy some tech for a company with a thousands of clients I want something what doesn't need my attention for every other client station. I need something robust what would work 99% of times and for a 1% what disbehave I can OR just change the environment so the client would run or drop a ticket to the guys who I am paying for diagmosing these things and after a couple of days or weeks: Just install a new version which would work OR Have the understanding how I can change the environment so it would work. The thing is what I don't need to spend my time on solving these things.