18 ms·
Tailscale has raised $160M
- th0ma5 1y agoWhat are the failure points of hosted solutions like Tail scale versus self hosted options?
- chgs 1y agoTailscale has a single management engine. My understanding is that if the goes your existing traffic will still flow, but new connections won’t be made.
- joemazerino 1y agoTailscale was invaluable for connecting my remote offices together. Long gone are the days of openvpn configs
- elAhmo 1y agoWhen I saw the new round, I was instantly worried about change in direction that will most likely come with this, and effectively drive away regular users from a tool that seems universally loved. Similar sentiment can be seen in the discussion from three years ago [1] when they raised $100M. [1] https://news.ycombinator.com/item?id=31259950 https://news.ycombinator.com/item?id=31259950
- braginini 1y agoTry netbird which is an open-source alternative to free yourself from worries xD https://github.com/netbirdio/netbird https://github.com/netbirdio/netbird
- 650REDHAIR 1y agoThank you for sharing this link! I was about to slog through AI search results looking for an alternative.
- drcongo 1y agoI've been tracking this space for a while just out of annoyance that Tailscale offers ssh on the free tier, then not on the "starter" paid tier. Netbird is by far the best of the alternatives that I've tried.
- CharlesW 1y agoTheir Personal Plus (the non-business "starter" plan) does offer SSH, FWIW.
- stavros 1y agoCan you comment a bit on what you liked about them, especially compared to Tailscale?
- drcongo 1y agoWell, it's important to start with saying I didn't like it as much as Tailscale, but I liked it a lot more than any of the others I tried. The UI for their dashboard is very good and getting it up and running was pretty trouble free though the docs could be a little better.
- stavros 1y agoAh, that makes sense thank you!
- mkl 1y agoHave you tried ZeroTier? Their free plan's been working well for me. I haven't tried NetBird.
- arcanemachiner 1y agoI've always been on the outside looking in, so I've never used Tailscale or its open-source brethren. Would this service be comparable to Headscale[0]? [0] https://github.com/juanfont/headscale https://github.com/juanfont/headscale
- _lvbh 1y agoHeadscale is server only. Netbird is the whole stack (basically does the same thing but completely different software/implementation)
- bjackman 1y agoBut the tailscale client is open source too
- Imustaskforhelp 1y agoDoesn't that also then make tailscale completely open source?
- udev4096 1y agoWhat? The original coordination server, which is not running headscale, is closed source so yes, they are still a closed source company
- bjackman 1y agoNo their "real" backend is proprietary. Headscale is a separate implementation that they also maintain. It's intended for self-hosting your individual Tailnet. I'm assuming if you tried to use it as a corporate VPN you would run into limitations. Their clients for proprietary OSs are at least partly proprietary too. To be honest I find this all a very reasonable set of compromises. It means I'm comfortable using their proprietary service without feeling like I'm getting locked into a completely closed ecosystem.
- pilif 1y ago
- resiros 1y agoI use personally for my home network. Very easy to use and quite mature. I'd highly recommend.
- regisso 1y agoI highly recommend netbird, after using it for two years. The whole stack can be self hosted is open source develop by an european based company.
- Valord 1y agoI share your concerns.
- pomatic 1y agoWhen they raised the 100M three years ago, I'm pretty sure they said they didn't need it and were saving it for a rainy day (or words to that effect), always seemed very odd at the time. Two q's for anyone who cares to speculate: have they burnt the original investment already? And if not, why would they need more funding? AFAICS there's no real competition in the market place for their product today, the only thing I can conceive is that they have a secret 'tailscale 2' project in the wings which is massively developer or capital intensive. Let's hope it is nothing related to AI band wagoning :-)
- chubot 1y agoHm OK well thinking out loud, $100M / 3 is $33M / year? I don't know much about Tailscale, nor about how much it costs to run a company, but I thought it was mostly a software company? I would imagine that salaries are the main cost, and revenue could cover salaries? (seems like they have a solid model - https://tailscale.com/pricing https://tailscale.com/pricing) I'm sure they have some cloud fees, but I thought it was mostly "control plane" and not data plane, so it should be cheap? I could be massively misunderstanding what Tailscale is ... Did the product change a lot in the last 3 years?
- fragmede 1y ago> I don't know much about Tailscale, nor about how much it costs to run a company $33m/year is only 33 fully loaded software developers including all overhead like HR and managers and office space, and also a cloud hosting bill. 33 really isn't that many.
- johnbellone 1y agoI'd be surprised if the average package for SWE is $1M/year (fully loaded).
- YetAnotherNick 1y agoGenerally package is around half of what company spends per extra engineer. And $500k average for a tech heavy product company doesn't sound too far off.
- specialp 1y agoThere are plenty of enterprises that will pay them to run their services and provide better integrations while allowing open source users to continue. Now people will get upset because some of these things will be for those customers only but it is very hard to keep developing these things and give them out for free. Partially open source still allows those to extend the work they give to the community and they will probably still continue to have a free tier to get more enterprise customers in the end.
- ilrwbwrkhv 1y agoThis is mostly so that the founders can take some money off the table. The founders probably have $10 million cash after this and don't have to worry about rent ever again.
- tptacek 1y agoThe founders of Tailscale probably weren't too worried about rent before Tailscale.
- ilrwbwrkhv 1y agoWhy? Did they have a previous exit?
- vvillena 1y agoIIRC they were senior engineers from Google.
- otterley 1y agoHow is Tailscale going to achieve at least $1B in annual revenue? That’s the kind of promise that would have to be made to investors in order to raise funding of this magnitude.
- datadrivenangel 1y agoBecome the provider of choice for enterprise IT networks or get bought by Azure?
- SparkyMcUnicorn 1y ago> get bought by Azure Please no.
- john2x 1y agoWe’re like trading cards to these people
- throw16180339 1y agoMy prediction is that they'll be bought by Cisco.
- tuananh 1y agoit would fit in very well with Cisco eco system
- borski 1y agoI imagine this was, at least in part, part of the pitch deck.
- baq 1y agoOne would hope they’d create something like Google drive except you own your stuff that people would pay for.
- fidotron 1y ago
- deleted 1y ago[deleted]
- sshine 1y agoso tailscale is selling out that was disappointing at least the current software is open source, so others can fork it before it closes down on itself and enshittifies.
- kube-system 1y agoTailscale is a software company founded in 2019 that raised their series A in 2020, not a grassroots community project
- sshine 1y agoso either you do it out of the goodness of your heart, or you maximize shareholder value at no expense I'd sell out at $160M, too. I'm happy for them, and sad for everyone else.
- hobofan 1y agoAs GP said, they have raised money before. So why are you now disappointed and think they "are selling out", when nothing has changed, and Tailscale has been a clear-cut for-profit startup from the start?
- brunoqc 1y ago> at least the current software is open source Not the server. headscale is nice, but it's not an official project.
- 4k93n2 1y agonetbird looks like it would be a better option if open source is what youre after. theres a handful of others too, nebula, zerotier, netmaker just to name a few
- mikkelam 1y ago[flagged]
- cadamsdotcom 1y agoGood. This lets them receive some of the value they’ve created (they should get paid!) and gives certainty they won’t go out of business. Which means more Tailscale now and in future! If they turn evil (unlikely with the current folks there) they’ve written up / open sourced plenty of what got them to this point. Don’t capture all the value you create. But you should try to capture some.
- briffle 1y agoThe same thing has been said about many other companies taking on VC Money. Someday, those investors are going to want to see a return on that investment. Its going to take focus and determination to not just ship enshittification as a feature..
- bananapub 1y agoit is a nice that they're a bit embarrassed about it and spend much of the post explaining why they took more money. overall, they still seem to have their heads screwed on straight and have an actual business model, that is also pretty fair - charge enterprises per seat to solve their network identity problems. anyway, keep up the good work, Avery and co.
- burningion 1y agoTailscale is a great. I think of it as a swiss army knife for easier routing and connectivity. I use it in projects to stream internet / connectivity from my phone to the NVIDIA Jetson line, making my robotics projects easily accessible / debuggable: https://github.com/burningion/bicyclist-defense-jetson?tab=readme-ov-file#bicyclist-defense-with-nvidia-jetson-orin-nano https://github.com/burningion/bicyclist-defense-jetson?tab=r...
- syntaxing 1y agoOff topic but rerun.io is really cool. Never heard of it until I saw your project. Do you know if it does "replay" kinda like rosplay?
- burningion 1y agoYes, rerun does replay, that was my main use case when prototyping. They've since raised more funding recently, and have larger use cases in mind for robotics: https://rerun.io/blog/physical-ai-data https://rerun.io/blog/physical-ai-data I've spoken with members of the team, and they're all great. Wouldn't hesitate to use the product / work with them anywhere.
- syntaxing 1y agoI can't seem to find the replay function. As in replaying the sensor data as if it was "live". Would you happen to have a link to this feature?
- nikonp 1y agoRerun co-founder here. Rerun doesn’t have replay in the sense of you send messages in and can play back the same messages in the same order later. We have playback in the sense that you can play it back in the viewer. We also have apis for reading back data but its more focused on dataframe use cases rather than sending you back messages
- 1y ago
- srameshc 1y agoI don't probably use Tailscale to it's full potential but I love this tool. We have our small servers at our offices across the world and it has give us so much flexibility to access some of the files via shared drives or try out installing / testing stuff. Me and my wife also drop each other pictures of our kids using tailscale now.
- suralind 1y agoOff-topic, but it makes me laugh that companies will list their “investors”, “advisors”, etc. on their company page, but not the people working there. That said, Tailscale is one of the products that just works.
- tptacek 1y agoI think they might be operating at a scale that breaks those kinds of pages at this point? Not literally, of course, just they're past the point where the page makes sense.
- Valien 1y agoYou can always find a lot of us on LinkedIn :D {I work at Tailscale}
- jedberg 1y agoCloudflare still has their about page with thousands of people: https://www.cloudflare.com/people/ https://www.cloudflare.com/people/
- xyst 1y agolol - wonder if HR or whoever maintains this site just scrapes the internal directory to generate the is page. Names/photos are not even clickable. Just first names and a photo. Thats so cloudflare.
- jackietreehorn 1y agoused to have last names, but it became a security concern. It is ordered by seniority.
- ewpratten 1y agoIt’s automated in the kind of way that makes a lot of sense to people familiar with the internal HR systems.
- 1y ago
- apitman 1y agoEven if it could mean Tailscale enshittifies eventually, this is probably a good thing for the ecosystem. As one example, the bigger they get, the more likely operating systems will build better APIs to support what they do (for example maybe Apple will provide a way to do mDNS over Tailscale), and those APIs can be used by all. There are plenty of open source alternatives cropping up[0]. I'm curious to see what Tailscale can do with a lot of resources. [0]: https://github.com/anderspitman/awesome-tunneling?tab=readme-ov-file#overlay-networks-and-other-advanced-tools https://github.com/anderspitman/awesome-tunneling?tab=readme...
- deleted 1y ago[deleted]
- LeoPanthera 1y agoApple had a Tailscale-style feature called "Back to my Mac" that was part of MobileMe. They killed it off with the rest of MobileMe, presumably because they just wanted you to store everything in iCloud.
- mrbonner 1y agoDoes anybody encounter issues with DNS after installing tailscale with it's MagicDNS enabled? It drives me nuts because my entire network just stops working. I removed tailscale but still won't be able to connect to my Ubuntu server.
- baq 1y agoYeah, you need to be conscious about your tailscale domain, your .home (or whatever your router or dhcp server advertises) and your .local hostnames. Even if you’re aware, things are sometimes wonky, IME primarily on macOS.
- saurik 1y agoI am on Arch and often end up with DNS broken in a way that requires me to restart tailscaled.
- nickzelei 1y agoI've had issues with tailscale dns for a while where I'll wake my mac up and the dns will just not work until I disable tailscale. I can then re-enable it and everything continues to work. I logged a bug about it and the latest versions this seems to have gone away. I also moved away from the mac store variant and into the standalone. Not sure if that helped either.
- fidotron 1y agoYeah, I honestly couldn't get Tailscale to work reliably at all. DNS, routing, firewalls etc. My overall impression was it will work if either you go for it on your entire local subnet, or you have a very simple local network topology. Having local nodes inexplicably talking to each other via a cloud relay basically all the time just isn't acceptable. (And webrtc could always find the local candidates when doing ICE, so it's not that). It's interesting because they have clearly demonstrated a demand for such a thing, but the "just works" pitch is a fantasy, at least today.
- evanjrowley 1y agoSometimes I have issues like this. It's related to my ISP not supporting IPv6. I don't have time to explain this in detail, but at least that's one angle of it that you might want to explore further.
- geenat 1y agoIMHO they should be a good steward and toss the Wireguard guy a mil considering Tailscale is pretty much Wireguard with a GUI on top.
- belthesar 1y agoTailscale is definitely more than "Wireguard with a GUI", but I don't think that diminishes your point that Tailscale, if they're not already, would be great stewards if they were contributing more than code back to the Wireguard project.
- aborsy 1y agoThis is not correct. Wireguard establishes a tunnel between peer A and B, and its simplicity stops there. Tailscale does tons of complex networking, filtering, nat traversal, DNS, file sharing, etc. Wireguard is a small part of the codebase today, which has grown a lot. It’s a bit like saying Dropbox is just a GUI on top of TLS.
- infinghxsg 1y ago[dead]
- homebrewer 1y agoMost of this was successfully done 20 years ago by tinc, which is a project written by a couple of European guys in their free time. It even supports routing traffic through other peers and does peer discovery just like BitTorrent (but before BitTorrent even existed) — there is no need for a central server. What tailscale has over it is hype, lots and lots of hype. Also a much more well thought out, and arguably more secure VPN protocol underneath, which is why GP's comment is on point.
- RealityVoid 1y agoAnd ease of use, IMHO. That's a bit one with these kind of things. I will admit not having used tinc but I imagine it's not as polished. Polish costs effort and money and it also really truly saves time and makes for a better product. So that matters.
- ignoramous 1y agoWhen we started Tailscale in 2019, we weren't even sure we wanted to be a venture-backed company. We just wanted to fix networking. Or, more specifically, make networking disappear — reduce the number of times anyone had to think about NAT traversal or VPN configurations ever again. Isn't logtail what got Avery et al started? https://github.com/tailscale/tailscale/tree/main/logtail https://github.com/tailscale/tailscale/tree/main/logtail https://apenwarr.ca/log/20190216 https://apenwarr.ca/log/20190216 / https://archive.vn/xlsA1 https://archive.vn/xlsA1
- everfrustrated 1y agoThat's quite insightful actually. Perhaps might explain the tailscale name a little better in that context also.
- tmpz22 1y agoIf they had taken just say $40 million would they be able to sustain their project for the foreseeable future and perhaps not yield as much future product direction and equity? I honestly don't know how this big dealmaking works but it strikes me that when you take out this big of an obligation that the obligation has a gravity that may drag you in a direction you (or consumers) do not want to go. Love Tailscale as a product (as does everyone I talk to) but genuinely want to learn more about the trade-offs as usually when we see big dollar signs all we do is celebrate.
- lazzlazzlazz 1y agoEquity investments like this don't need to be repaid, so there isn't a legal obligation to repay them. Of course, there is an obligation to maximize shareholder value — but that is totally independent of the dollar amount invested. When founders raise this much money, it's because there's (1) a lot they want to do and hire for, or (2) they don't want to worry about monetizing the product for a significant period and focus on growth or product development.
- mitthrowaway2 1y agoGP didn't talk about "repaying" anything. Taking 160M instead of 40M at the same valuation means giving up 4x the shares, and that's going to result in a bigger voice for those investors at the table in making decisions about the future path of the company.
- firloop 1y agoWhat if they were offered $160mm and Tailscale countered with 4X the valuation, lowering the number of shares by 75%? Similarly, what if they wanted $40mm but the only deal on the table was $160mm due to ownership targets of funds that can actually write $40mm+ checks? It's hard to play these armchair games, even less so when the terms aren't known.
- santoshalper 1y ago
- aborsy 1y agoTailscale deserves it. They have produced excellent software.
- devmor 1y agoDepressing news, I have no hope that the countdown to Tailscale being unusable subscription trash has not started with this announcement. I realize this is a very ironic place to make this statement, but I am utterly exhausted by VC money destroying all of the services I enjoy, like a slow disease spreading through a herd of livestock.
- slig 1y agoThey have raised before, so that money helped shape the service you enjoy.
- elevation 1y agoInvestors expect that Tailscale will extract many multiples of their contribution from users. If you'd like to avoid this extraction, you can fork their command line client code (along with the open source headscale server) and run a mesh network across your linux machines with all the magic DNS and userspace-TCP/IP-stack goodness that you're used to. Tailscale has given away a lot of the engineering for free. However, as soon as your fork becomes incompatible with Tailscale's stack, you lose a massive value-add: proprietary platform support. Today, you can add the sale's guy's iPhone to your tailnet in seconds. If Apple's capricious automated AppStore security pulls the Tailscale app from the AppStore, Tailscale Corp is big enough to get Apple's attention. A small FLOSS group with some forked clients on github won't be able to provide this same operational stability.
- codethief 1y agoEveryone is commenting on the HN headline, no one on the actual post: > Building the New Internet (Insert mandatory reference to Silicon Valley here :)) > We think there’s a better way forward. We're calling it identity-first networking. I would love to see this. Every day I have to stare at YAML files with IP addresses in them is a day I will never get back. I wish cjdns[0] had succeeded already but oh well, now I hope the Tailscale guys will! [0]: https://github.com/cjdelisle/cjdns/ https://github.com/cjdelisle/cjdns/
- transpute 1y agoOperant has something similar in IIoT, https://operantnetworks.com/sie-sbd-part2/ https://operantnetworks.com/sie-sbd-part2/ 1. Immutable Content Naming: In a data-centric system, content is addressed by its name, transcending geographical considerations. This circumvents the vulnerabilities associated with IP addresses, which can be spoofed or manipulated. By employing cryptographic techniques to validate the authenticity of content names, NDN establishes a robust layer of security that underpins the entire architecture. 2. Built-In Data Integrity: NDN employs built-in mechanisms to ensure the integrity of data. Content is signed by publishers and verified by consumers, preventing tampering or unauthorized alterations. This approach effectively mitigates data breaches, as any unauthorized modification is detected and rejected.
- codethief 1y agoThis is about data, though, not about addresses, is it?
- transpute 1y agoIt's both, https://en.wikipedia.org/wiki/Named_data_networking https://en.wikipedia.org/wiki/Named_data_networking > NDN has its roots in an earlier project, Content-Centric Networking (CCN), which Van Jacobson first publicly presented in 2006.. NDN applications name data and data names will directly be used in network packet forwarding.. Its premise is that the Internet is primarily used as an information distribution network, which is not a good match for IP, and that the future Internet's "thin waist" should be based on named data rather than numerically addressed hosts. NDN talk by Van Jacobson at Google (2006): https://www.youtube.com/watch?v=oCZMoY3q2uM https://www.youtube.com/watch?v=oCZMoY3q2uM
- jncfhnb 1y agoFingers crossed they’ll finally enable sending files to people
- mrdoornbos 1y agoThis sort of thing tends to trend bad for users.
- segmondy 1y agowoot, woot, happy for the team. I love tailscale and can't stop singing praises.
- nottorp 1y agoEntshittification incoming?
- nextworddev 1y agoYou know it
- finnjohnsen2 1y agoI just wished their server side was open source also
- flkenosad 1y agohttps://github.com/juanfont/headscale https://github.com/juanfont/headscale
- rounce 1y agoIt’s pretty hobbled compared with OG Tailscale, so much so that I moved completely to self-hosted NetBird and haven’t looked back.
- beng-nl 1y agoThere is a open source clone for the Tailscale server named headscale fwiw.
- amriksohata 1y agoWhat's the difference between this and say azure vent and configuring that with private endpoints
- breakingcups 1y agoOh no. That's really too bad. Fingers crossed they'll beat the VC curse because it is so close to perfect as it is right now.
- tonymet 1y agoanyone care to share how they are spending money? labor, operations (training, transfer fees), marketing & business development. It's different than industries I'm more familiar with.
- deleted 1y ago[deleted]
- maxclark 1y ago$33m/year burn accelerating to $50m+/year Profitability and exit math just got harder I love the service and am rooting for them - I just don’t get this cash outlay I can’t wait to learn what I’m missing here
- xyst 1y agoHope this means headscale involvement doesn’t get 86’d. As I recall, a few tailscale folks contribute to this open source implementation of the “coordination server”. Apparently tailscale management approved it. So this means management at any time can revoke it, and possibly kill off self hosting of the coordination server as the open source clients become incompatible.
- robinhood 1y agoEnshittification will start in 3... 2... 1....
- Uzmanali 1y agoTailscale just got a lot of money to keep growing. But what they are doing is more important than the money. They are helping computers talk to each other in an easy and safe way. Before, the internet was built to connect places, not people. That made things messy. People had to set up tricky stuff like VPNs and firewalls. Tailscale makes this much easier by using your name or account, not just numbers like IP addresses. Now, big companies and people at home use Tailscale to keep their computers and apps connected. It works without a lot of setup, and it’s safe. Even people building smart robots and AI are using it. What’s really good is that Tailscale still helps small users for free, and they try hard not to break anything when they update their tools. If they keep doing that, they can become a very important part of how the internet works in the future.
- briHass 1y agoI'm a fan of TS and have been a paying customer for work infra for almost a year now. It really is well put together and easy to use, but I do run up against some issues/complaints when diving deep that I hope they can work out: * The pricing tiers and included features by tier penalizes you in frustrating ways. The base plan is a reasonable $6/user/m, but if you want to use ACLs to control anything in a workable way, it jumps 3x to $18/u/m. Better solutions are available for that kind of money, and I shudder to imagine what the next tier ('call us') costs. * Subnet routing broke on Ubuntu (maybe other distros) recently, and there were no alerts, communication from TS, or TS tools to pinpoint/figure out what was going on. I stumbled on a solution (install subnet router on a Windows box), and from there I searched and found others with that issue. Lost half a day in emergency mode over that! * Better tooling to determine why it's falling back to DERP instead of direct for remote clients. DERP relays should be an absolute last resort to provide connectivity for Business-plan-level customers (very slow), and the way TS works just assumes any connectivity is fine. Overall, the simplicity and abstraction of complex VPN networking is wonderful, but if you have issues or advanced needs, you are immediately thrust into the low-level UDP/NAT/STUN world you were trying to avoid. At that point, you're better off using a traditional VPN (WG, OpenVPN, or heaven forbid, IPSec), because it ends up being more straightforward (not easier) without the abstractions and easy-button stuff.
- smashed 1y ago> * Better tooling to determine why it's falling back to DERP instead of direct for remote clients. DERP relays should be an absolute last resort to provide connectivity for Business-plan-level customers (very slow), and the way TS works just assumes any connectivity is fine. Tailscale touts all the perf benefits of the wireguard protocol but in practice between the userland wireguard that seems to be used all the time on all platform (even linux) and the over reliance on DERP, it has none of the performance benefits of the real thing.
- miki123211 1y agoThey also seem to be needlessly doing DERP over TCP in some cases where UDP would actually work.
- karaterobot 1y agoFunny how, as soon as I hear about a big new funding round, my reaction is sadness because I assume the product is going to start being bad and user-hostile in about 6 months. It shouldn't be that way, but it's just a reflex after seeing it happen so often.
- jayloofah 1y agoAs an alternative there's https://github.com/tonarino/innernet https://github.com/tonarino/innernet
- ErigmolCt 1y agoThe shift toward identity-first networking is also super interesting. Feels like we're finally moving past the idea that IPs = trust, and into a world where access control actually maps to human (or service) intent
- wg0 1y agoStart looking for alternatives already. Nothing good came out of VC rounds and private equity for the end consumers ever.
- sidcool 1y agoI understand the cynicism. But this is counter productive. Any venture has to have a finance angle. They are not missionaries.
- LunaSea 1y agoSure, but amounts matter.
- wg0 1y agoAll in for profitability and financial activity. That's the very foundation of innovation. But VC funding works very differently.
- BiteCode_dev 1y agoSteam does fine financially and without having to answer investors, which is why it's been able to stay mostly good to its user base for so long. This is not an "xor" statement.
- wg0 1y agoSo is Basecamp. Profitability is not a dirty word.
- afroboy 1y agoWhat's wrong with Steam (Valve) business model?
- mbs159 1y agoVC funding is on a whole other level, though
- sidcool 1y agoCongrats TS. You deserve this.
- LWIRVoltage 1y agoI just this past weekend was looking into setting up a personal networking solution- and looked hard at TailScale and their competitors. I do not like- that Tailscale has chosen to only allow SSO sign-in - as that forces one to have a Microsoft,Github[MS], Google, or Apple account- and I presume that leaves one at the mercy of those companies for the free option. I will probably eventually cave and use my main account from one of those companies since creating true secondary accounts can be difficult(they end up tied back to your main account on the backend usually, So if something happens to one or the company does something- it'll affect everything and building separation is not easy.) - But I dislike that sort of design.
- moontear 1y agoThis is not true. You can run Tailscale with a custom self hosted OIDC provider such as Authelia. https://tailscale.com/kb/1240/sso-custom-oidc https://tailscale.com/kb/1240/sso-custom-oidc
- lloeki 1y agoInteresting. I didn't know that you could also use e.g codeberg this way.
- cab11150904 1y agot weekend was looking into setting up a personal networking solution- and looked hard at TailScale and their competitors. I do not like- that Tailscale has chosen to only allow SSO sign-in - as that forces one to have a Microsoft,Github[MS], Google, or Apple account- and I presume that leaves one at the mercy of those companies for the free option. What is going on with your sentences man.
- globular-toast 1y agoWhat is their use case in an IPv6 internet? Or is this another company with a vested interest in stopping IPv6 from happening?
- pmb 1y agoThey are a zero-trust networking solution that also traverses IPv4 NATs. Zero-trust networking is a layer above the IP layer. In an IPv6 Internet their capital costs go down, and their product remains valuable for their paying customers. (Free accounts mostly use it for NAT traversal, businesses for the zero-trust encryption.) Their CEO has been working with (and supporting) v6 for decades both at the executive level (now) and also as an extremely capable software engineer that I personally met with a few times while we were both engineers at Google doing network measurement.
- werrett 1y agoI've got conflicted feels about Tailscale. I love their product and a bunch of the people I know use their free tier, including myself. But their enterprise strategy destroys their good will. I can only assume it's focused on killing old school VPN products. The free tier that we love is a marketing expense. And it’s not even a conversion play. People are complaining about ~10/user/month -- add basic things that you'd need to manage more than 10 peeps (SAML/SCIM support) and you're talking ~20/user/month. For us, a small sub 200 person company, they immediately lost their chance. We have lots of problems in the security space, some we're willing to spend more than 20/user/month to solve. Legacy network access is not one of them.
- jackhalford 1y agoIf 20$/user/month is too much, maybe you could apin up headscale and plug in your OIDC provider? Never tried it myself, I only manage small tailnets so the free tier is fine
- socksy 1y agoAssuming they wouldn't want to take on server maintenance workload, wouldn't something like NetBird be a better fit? The free version has ACL already, the $5/user/month has OIDC integration, and the business version (MDM integration and auditing) is $12. Then the server is still open source so if they wanted to transition to doing it themselves they still would have that option down the road.
- jen20 1y ago> I can only assume it's focused on killing old school VPN products. Given how goddamn terrible Cisco anyconnect is, I hope they succeed.
- littlecranky67 1y agoStill can't wrap my head around that TS does not allow to signup with your custom email/password combination but forces you to use bigtech (GitHub, Apple, Meta etc.) to login. Running your custom OIDC provider as a small, private person does not make any sense either.
- dijit 1y agoI think that's quite smart, and OIDC is an open standard at least. Securing usernames/passwords and handling second factors etc; is already done so well and it's hard to do. Having a clear 'this is where we can be secure' stances is what makes me want to trust them more.
- littlecranky67 1y ago> and OIDC is an open standard at least But what kind of argument is that, if you are a single individual who wants to signup, I am not going to setup my OIDC servers. That is like saying it is a good idea to run a dedicated linux server in a datacenter under your own management, when all you want is a small static website for your mom+pop store. Sure, you can run your own server and it is all open source, but just overkill. > already done so well and it's hard to do. So hard that literally all other websites in the world with a login have implemented it. And tailscale is a VPN-like technology company - if they can't manage to implement a login because it is hard, then I would definitely not accept their offerings.
- guappa 1y agoIt's an open standard, but would they allow me to use my OIDC?
- dijit 1y agoYes, they allow that.
- lo0dot0 1y agoWhy is that smart? I signed up for a Microsoft Account with my email and I can use Microsoft Account to log in to Tail scale but I can't use the email directly? How does the middle man bring anything to the table?
- 00deadbeef 1y agoI like Tailscale and we pay for it at work but it has a number of serious bugs that affect our work that they seem to lack the resources to fix. Hopefully this helps.
- udev4096 1y agoMaybe try out promising alternatives such as netbird, teleport, zerotier, etc
- asim 1y agoCongrats to the tailscale guys. I remember when tailscale was not a networking company. Amazing to see where it's ended up and obviously having bradfitz onboard is useful too. I'm always curious to know what the internals of a company looks like with a lot of ex-googlers running it. Does it look like a mini Google or something else? Not sure if apenwarr is here but always interested to learn more.
- PeterStuer 1y agoGlass half full customer: great, the service I rely on is going to persist! Glass half empty customer: OMFG, this is the minimal amount they are going to bleed from us over the next 5 years! Based customer: this is just a half filled glass, full or empty is just your projection.
- teleforce 1y ago>Connecting GPUs across clouds, securing workloads across continents, migrating between cloud providers — it’s messy, it’s hard, and it breaks all the time. Is the new fund raise to enable Tailscale perform these complex tasks or for scaling it? I've once read few years back that seamless and secure cloud independent computing or cross-cloud system is the next frontier, and it seems it's a legit problem and a business opportunity for security company like Tailscale and Crowdstrike (investor). The record breaking acquisition of Wiz kind of cemented this problem space and the pain points, and it seems that Tailscale is riding on the opportunity [1]. [1]Google to buy Wiz for $32B (845 comments): https://news.ycombinator.com/item?id=43398518 https://news.ycombinator.com/item?id=43398518
- debarshri 1y agoIt is commendable that TS has created a market in an already crowded marketplace of VPN tools. They're competing with Palo Alto, Netskope, Check Point, and Cisco, to name a few. One key understanding from my brief market experience is that you must build a firewall or router if you really want to own the VPN market. The way the sale is done is that the vendor goes in with the firewall, router, and switch, offering office space connectivity with the infrastructure and various network locations and upselling the VPN. This often accounts for the subpar quality of VPN software. There is a trend called SASE, which includes technologies like TS; people are questioning the enterprise value of SASE. Netskope and Cato Networks are some examples. I believe that their enterprise journey will be challenging, given the player's extensive experience in upmarket sales. Although TS appears appealing and has potential for improvement, the GTM is entirely unique for enterprise. You need to build reseller network, System integrator partners, high value customizations, etc. If you decide to embrace the security positioning, you must have a diverse portfolio of products. If you model the org. around Palo Alto et al., you need a huge diversity of products, VPN, hardware, cloud security tools, app security tools, etc., as the ICP (CISO) is trying to optimize their allocated budget. People in enterprise are ok with good enough products as long as they meet compliance standards, fit the budget, and does not disrupt operations. It could be that they might acquire bunch of companies with this capital.
- udev4096 1y agoYou are still trusting the tailscale coordination server for proper key exchange. Yes, traffic is end-to-end encrypted and the private keys stay on the device but there's no way to verify that tailscale is negotiating keys for the machine you asked for
- supermatt 1y agoIm pretty sure thats not correct, as you can authorise the nodes that get added, and it is only authorised nodes that can participate in the tailnet. The problem IIRC is that it is the coordination server that decides what is authorised, so if Tailscale was hacked (or otherwise malicious), nodes could get added to your tailnet without explicit authorisation from the tailnet "owner", which is obviously not good. To prevent this, they introduced tailnet-lock, which requires other peers to participate in node authentication: https://tailscale.com/kb/1226/tailnet-lock#how-it-works https://tailscale.com/kb/1226/tailnet-lock#how-it-works
- Shorel 1y agoGood call, I started using it a few months ago, and now it is something I can't live without.
- littlestymaar 1y agoTailscale not having reached profitability yet and having to raise more is bad news, as it increases the odds of future enshitification.
- curtisszmania 1y ago[dead]
- johntopia 1y agocongrats to the tailscale team
- LinNight 1y ago[dead]
- LinNight 1y ago[flagged]