4 ms·
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer to
by behnamoh 2mo ago
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
- traceroute66 2mo ago[flagged]
- aborsy 2mo agoIt does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity. I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it. Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
- k8sToGo 2mo ago> I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it Doesn't this apply to any application you use? How would it be different with plain wireguard?
- traceroute66 2mo ago> How would it be different with plain wireguard? Seriously ? You do realise that of all the security tools on the planet, plain wireguard most likely has the smallest attack surface of them all, right ? The problem here is as the other poster said. Tailscale is a security tool and yet the guys at Tailscale seem to be insistent on dumping everything INCLUDING the kitchen sink into it as a "feature". That sort of attitude is not going to end well. You end up with a large bloated code base, which equals large attack surface.
- k8sToGo 2mo agoI am talking especially about the LLM part. Also a kinder tone in your comments would be more appreciated.
- stonedivot 2mo ago[flagged]
- aborsy 2mo agoNo. If software is small enough, it can be proven. There is formal verification of the protocol and aspects of code: https://www.wireguard.com/formal-verification/ https://www.wireguard.com/formal-verification/ The code is small enough that can be reviewed.
- k8sToGo 2mo agoThat makes sense. Thanks!
- r0b05 2mo agoThe large attack surface is a good point. I started using it initially and the ease of setting up a vpn was nice, but then I came across few security vulnerability postings which led to concern so I went to Wireguard. I think they should reign in the features and treat it as a secure vpn first and foremost and remove unnecessary features to minimize the attack surface.
- inigyou 2mo agoIf you want a hard-to-use VPN with minimal features and minimal surface area, as you said, Wireguard is right there. Tailscale is convenient Wireguard.
- icedchai 2mo agoI use Wireguard for several site-to-site VPNs. It just works. I never have to worry about it, and there are very few configuration settings to mess up (unlike, say, IPsec, which is a nightmare.)
- inigyou 2mo agoYes, for a permanent site-to-site link. Now try configuring 300 nodes in a mesh, where nodes are coming and going every half hour.
- AlphaSite 2mo agoIf you architect properly it doesn’t necessarily follow that more features means more attacks, or certainly not more system wide attacks. If you layer and segment correctly you can build atop a secure core and have some decent security.
- apenwarr 2mo ago(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you perhaps imagine to be a long list of vulnerabilities... doesn't look like that. It says we don't have a long list of vulnerabilities. The security bulletins are all here: https://tailscale.com/security-bulletins https://tailscale.com/security-bulletins
- traceroute66 2mo agoThe majority of your security bulletins are as the result of third-party reports to you. Which, by definition, means they are not done by you, which means you don't know when they will be done or how much of your code base they are looking at. I think you know full well what I mean by a security audit. If you don't, go look at, for example, the ones that Mullvad publish for their software https://mullvad.net/en/blog/tag/audits https://mullvad.net/en/blog/tag/audits. Please do not try to portray SOC2 as being the same thing as a code audit. And IF you have regular code audits, then please publish suitably redacted reports in public on your website. Just like everyone else does !
- apenwarr 2mo ago(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins. Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin.
- traceroute66 2mo agoBut why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ? Those are an ancient class of bugs that should be picked up by any competent security review.
- darkteflon 2mo agoFor me, the calculus is simply: “there’s no way I could do this better than Tailscale”.
- tshaddox 2mo agoThat's true, but for some things I require a bar much higher than "at least as good as I could do."
- madeofpalk 2mo ago“there’s no way I could do this better than Tailscale” is a much higher bar than "at least as good as I could do."