4 ms·
> Why on Earth would I want to use a security product that phones home... Regular WireGuard works perfectly fine for me. Then you should continue using regular
by voidwtf 4y ago
> Why on Earth would I want to use a security product that phones home... Regular WireGuard works perfectly fine for me.
Then you should continue using regular WireGuard. However, modern industry is plagued by an endless war with vulnerabilities, exploits, and malicious insiders. Even with adequate staffing, it's like a dam you're constantly patching to prevent leakage. We have to log everything, often offsite, and often into immutable storage. When the dam does eventually leak, we have to know how much and how it started. The logging is a feature to me.
Tailscale is building a service that doesn't require me to run and maintain a centrally connectable server, one that ties into a single-sign-on solution, one that logs activity, one that's introduced a system in which I don't even have to trust their control plane exclusively (Tailnet Lock). Just the seemless integration with Azure AD has saved maintenance time over NPS+Radius+ADConnect+OpenVPN.
Wireguard is great, I'm using it for all my site-to-site still (and it blows OpenVPN out of the water). But Tailscale has replaced all my client vpns for good reason.
- ilyt 4y ago> When the dam does eventually leak, we have to know how much and how it started. The logging is a feature to me. Logging is a feature. Logging to some random 3rd party is not. Sure, if the 3rd party provides the service itself they need the logs to make it better but if stuff stays within your own infrastructure it should not phone home. And VPN service for enterprise certainly shouldn't have controller hosted on outside of company's own infrastructure
- unethical_ban 4y agoHoo boy, don't look up "Prisma Access" or "the cloud".
- ithkuil 4y agoWell it's not a "random" 3rd party, it's a company you decide to rely on for your security. You pay, they offer you a service. If you don't trust them, that's fine, the product+service isn't for you. But it's not a "random" 3rd party.
- etc-hosts 4y agoI had a hard time getting Wireguard to work with mobile android clients. Gave up eventually and now just use Nebula.
- stavros 4y agoReally? I use the (official?) Android and it worked for me fine first time, and has for years. I think maybe you ran into a UI bug where it wouldn't work unless a subnet definition ended in a 0 (ie defining 192.168.0.1/32 would cause it to silently not boot up).
- etc-hosts 4y agoI'll have to try that out. I also would like to be able to use my home lan DNS server for home lan hosts. It might not be a Nebula problem, but to do this I need to use DNS-over-tls in Android, through the Nebula tunnel. Edit: noticed you were referencing the WIREGUARD phone app. I'll go try harder.
- stavros 4y agoAh yes, sorry, WireGuard app. Let me know how it goes!