Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PLG88
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
PLG88
1y ago
There is tons of competition for Tailscale. Its 'just' an easier to use VPN with a great GTM exceution. I think they need more money as they need to fundamentally re-architect their solution to sell into enterprise use cases they
32.
▲
by
PLG88
1y ago
I think you mean to say: The. fine. article. seems. to. say. lots. of. companies. are. using. Tailscale. to. connect. to. servers. with. GPUs. -- nothing. in. that. implies. that. Tailscale. would. own. the. GPUs. Besides my joke, you are b
33.
▲
by
PLG88
1y ago
Agreed. This is why imho Tailscale does not scale very well. Awesome for home labs and small orgs as a VPN replacement, but not enterprise scale with abstrations that actually remove complexity. I wrote about it in this blog - https:/
34.
▲
by
PLG88
2y ago
'Cross-cloud chatter', 'Multicloud isn’t a (security) model citizen', all the networking primitives part (load balancers, firewalls, and delivery networks (aka DDoS protection)) of 'Time to frag your conf', as
35.
▲
by
PLG88
2y ago
You comment kicked off a big internal chat, which led to someone creating a document on our overlay approach, vs service meshes. I took that, wrote some extra details, comparison and summary - https://docs.google.com/documen
36.
▲
by
PLG88
2y ago
Yes, but the risk posture is very different. The question I like to ask is, 'what does it take to exploit a listening port on the overlay to get to a service': - (1) need to bypass the mTLS requirement necessary to connect to the
37.
▲
by
PLG88
2y ago
Thanks for the feedback, tons in there. - Agreed. OpenZiti is not trying to focus on indie hosts. It has the goal to completely transform how networking and connectivity are done, to make secure by default and a simple user experience the d
38.
▲
by
PLG88
2y ago
My guess is that is how they want to commercialise, they make that bit harder so that more people pay for their hosted solution. I have sympathy, monetisation allowing maintaining FOSS can be a challenge. We all have bills. I agree with a l
39.
▲
by
PLG88
2y ago
We use very light weight libraries - https://openziti.io/docs/learn/core-concepts/security/connec... - incl. mbedTLS (from Arm) and ChaCha20-Poly1305 (same as Wireguard) by default. We have tons of use c
40.
▲
by
PLG88
2y ago
OpenZiti is developed and maintained by NetFoundry ( https://netfoundry.io/ ). We provide a productised version which is very easy to deploy, manage, operate, and monitor with high SLAs, support, legal/compliance, liabil
41.
▲
by
PLG88
2y ago
I see I did have a misunderstanding. I believe there is still the meta data angle, but yes, private keys on endpoints would ensure E2EE. I will update my comment.
42.
▲
by
PLG88
2y ago
Comment edited due to an incorrect understand which has been rectified.
43.
▲
by
PLG88
2y ago
I will preface by saying I am not a Nebula expert, and it may have changed since I last looked. Similarities: - Fully open source, using CAs as strong identities (rather than relying on SSO from third parties), completely self-hosted (with
44.
▲
by
PLG88
2y ago
Check out OpenZiti. Its open source, and does zero trust principles better. I wrote a blog comparing it and Tailscale - https://netfoundry.io/vpns/tailscale-and-wireguard-versus-ne...
45.
▲
by
PLG88
2y ago
Check out OpenZiti - https://openziti.io/ . It looks like Tailscale but is open source, takes zero trust principles to its logical conclusion, and includes a whole suite of SDKs (alongside host based tunnelers and VMs) makin
46.
▲
by
PLG88
2y ago
Probably fine for a home lab, I don't think its fine for a production organisation running critical services across the overlay.
47.
▲
by
PLG88
2y ago
Particularly as it does not include its own PKI, so E2EE is done by MITM your IdP (OICD/SAML etc) and therefore, under court order Tailscale can decrypt your traffic. We took the opposite approach with NetFoundry. (1) We open sourced t
48.
▲
by
PLG88
2y ago
Even Google admits BeyondCorp could not replace all their VPN needs... I wrote a Reddit post on it a while back - https://www.reddit.com/r/zerotrust/comments/1bfb7od/thoughts...
49.
▲
by
PLG88
2y ago
Great insights, I think you will like OpenZiti, Anders, which is included in your list for both itself and zrok, which we built on top. Directly answering your concerns: - Deny by default and least privilege model means getting access to a
50.
▲
by
PLG88
2y ago
For replacing port forwarding, OpenZiti definitely works. zrok, which is built on top of OpenZiti, could also be a great option for sharing resources - https://zrok.io/
51.
▲
by
PLG88
2y ago
or one of the many alternatives - https://github.com/anderspitman/awesome-tunneling . I will advocate for zrok.io as I work on its parent project, OpenZiti. zrok is open source and has a free (more generous and capable)
52.
▲
by
PLG88
2y ago
Check out zrok.io. zrok is open source and can be self-hosted (as well as having a free SaaS). I work on its parent project, OpenZiti.
53.
▲
by
PLG88
2y ago
Lacks the SDKs which provide the "at the application layer" the commenter requires.
54.
▲
by
PLG88
2y ago
Sounds like ngrok SDKs ( https://ngrok.com/categories/sdks ), but its closed source so I guess falls foul of your 3rd party solution comment. Another option could be zrok ( https://zrok.io/ ), which is an
55.
▲
by
PLG88
2y ago
Dont forget you can have open source security tools, e.g., the one I work on, OpenZiti, a zero trust network overlay - https://openziti.io/ .
56.
▲
by
PLG88
2y ago
Whole bunch of alternatives too - https://github.com/anderspitman/awesome-tunneling . I will advocate for zrok.io as I work on its parent project, OpenZiti. zrok is open source and has a free (more generous and capable)
57.
▲
by
PLG88
2y ago
Is TideCloak open source? When I search on Google I find this - https://github.com/tide-foundation/tidecloak
58.
▲
by
PLG88
2y ago
"How to Implement Zero-Trust Security in Software Development", I am surprised the article does not mention OpenZiti - https://openziti.io/ - from NetFoundry. It quite literally provides zero trust security and ov
59.
▲
by
PLG88
2y ago
You could do this agentless if you used open source zrok and/or OpenZiti, as they include SDKs to embed zero trust networking directly into your apps. I wrote a blog on this recently for Mendix, as a low code platform, which we demonst
60.
▲
by
PLG88
2y ago
Thanks. Spoke to dev, "building debugging tools has been in the backlog for a very long time. we have finite resources... it just hasn't made it to the top of any list". I will try to remember replying once we do have it.
More ›