4 ms·
Making heads or tails of open source
- operator-name 4y ago> two weeks ago we welcomed Kristoffer Dalby as the newest Member of our Technical Staff. Kristoffer is one of the principal maintainers of Headscale. > Although Kristoffer is joining Tailscale, we don’t plan to change how Tailscale works with Headscale. We’ll continue to support Headscale as a complementary project to Tailscale — with its own community of users and developers. It'll be interesting to see how this goes. I'm a big fan of tailscale and the work they do, but historically these kind of moves never play out how how anyone intends them to. I hope they the headscale project continues to live on, and continues to have seperate development from Tailscale's internal implementation to meet the needs of the community. Self hosting Tailscale beacons is more than just a "want", or a "desire" for DIY. It's fundimentally about privacy and trust - ANY VPN coordination server has a lot of power as we've seen from compromised business networks. The coordination server has ultimate control, and a malicious one could easily insert their own clients, hijack DNS or even just passively monitor devices. Overall I'm cautiously optemistic, but will probably throw a sponsorship towards Headscale even though I'm currently on the official servers.
- db48x 4y ago> The coordination server has ultimate control, and a malicious one could easily insert their own clients, hijack DNS or even just passively monitor devices. This is true, but I feel that it is important to say that with Tailscale the traffic between your machines doesn’t travel through any central server. Machine A and machine B send encrypted traffic directly to each other. The coordination server just authenticates them and tells them each other’s public keys, so that the machines can encrypt traffic going to the other and decrypt traffic arriving from the other. You can absolutely monitor that encrypted traffic to ensure that it is not being sent somewhere unexpected. If you want to route traffic from your phone to the wider internet you will have to provide an exit node of your own, so Tailscale doesn’t even have to deal with that headache either. It’s a really nice design.
- operator-name 4y agoYes, under normal circumstances (you trust the coordinator) its a really elegant system. I've not enumerated it all, but there's a _lot_ that a compromised coordinator can do. > You can absolutely monitor that encrypted traffic to ensure that it is not being sent somewhere unexpected. By the point that you do this at scale with your whole fleet, you'd almost be better off just setting up the tunnels yourself. This is also assuming your devices don't need to do NAT traversal (which is honestly one of my favourite parts of Tailscale). There's a lot more a malicious actor in control of the coordinator could do, even for preexisting connections.
- db48x 4y ago> By the point that you do this at scale with your whole fleet, you'd almost be better off just setting up the tunnels yourself. I suppose you are correct, if you regularly have traffic between every pair of nodes in the network. But I suspect that most companies have a lot of laptops that only talk to some datacenter/office via the VPN plus Gmail/O365/whatever via HTTPS. Monitoring in that situation is very easy.
- chipsa 4y agoIf you're paranoid enough to think about the coordinator getting hijacked, you can also have each of the clients send up their logs to your splunk or whatever server, and correlate them together (double entry logging, anything that doesn't have a match is probably wrong). Should be able to do the same for DNS: anything that's not a ts.net domain getting queried against the tailscale coordinator server isn't right, etc.
- biomcgary 4y ago>We know that someone could take the Headscale code and try to compete directly with Tailscale, but we hope they won’t. I think Tailscale has a reputation that would beat any rando trying to do this, but given the history of open source usage at a certain large cloud platform, is there any reason they wouldn't offer a rebranded service using headscale?