Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PLG88
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
PLG88
2y ago
Which part of the domain setup was complicated? Curious on how we can streamline/improve (or may have already). Excuse my ignorance, trying to get to the root why, why is replay fundamental for webhooks and integrations?
62.
▲
by
PLG88
2y ago
Why not just use one of the many open source ngrok alternatives - https://github.com/anderspitman/awesome-tunneling . I will advocate for zrok.io as I work on its parent project, OpenZiti. zrok is open source and has a
63.
▲
by
PLG88
2y ago
I am very curious, because I do think they are unambiguously a good thing.
64.
▲
by
PLG88
2y ago
If mTLS is combined with outbound connections, then IP source whitelisting is irrelevant; the external network cannot connect to your resources. This (and more) is exactly what we (I work on it) built with open source OpenZiti, a zero trust
65.
▲
by
PLG88
2y ago
The edge SDKs do not parse and interpret data from the internet, they provide ingress/egress off the overlay. They authenticate and authorise to the controller and make outbound connections to the overlay network. This is why any app e
66.
▲
by
PLG88
2y ago
I may be off base, but as the world moves to zero-trust networking, we can always embed a zero-trust network into our C++ app so that it can be distributed across the network while having no listening ports on the underlay network - i.e.,
67.
▲
by
PLG88
2y ago
Love zrok.io, I work on its parent, OpenZiti. It makes me wonder; OpenZiti makes PKI much simpler while providing the secure overlay, we even used our SDKs to demonstrate zero trust overlay networking built into MQTT - https://gi
68.
▲
by
PLG88
2y ago
Thanks! And good question, lets unpack a few things: - OpenZiti is opinionated on trust and thinks PKI is the best way to ensure every element in the private overlay network uses secure identity-based authentication and authorization. Thus
69.
▲
by
PLG88
2y ago
Thats one interpretation... ZT also posits assuming the network is compromised and hostile, that also applies to CF and their cloud/network. It blows my mind that so many solutions claim ZT while mandating TLS to their infra/cloud
70.
▲
by
PLG88
2y ago
My problem with this guide is that by using a VPN/Firewall combination there is a lot of inherent trust in the underlay network through the use of listening ports with inbound connections allowed. This means external actors can scan th
71.
▲
by
PLG88
2y ago
We dont disagree. As I stated, "These things have different purposes". If you want to publicly share a resource, use a tool which provides that in the knowledge that if there is a vulnerability, it could be exploited. Using an ove
72.
▲
by
PLG88
2y ago
Agreed. It surprises me that many of these services do not either lead with auth or have it as an important secondary. For many, port forwarding is a pain, so it solves that, but the security IMHO is just as important. It's a shame lis
73.
▲
by
PLG88
2y ago
The main difference is that Pinggy works via a public IP, whereas Tailscale is a private network overlay. Pinggy falls into the bucket of solutions like ngrok, zrok, Tailscale 'Funnel', Cloudflare Tunnel etc.
74.
▲
by
PLG88
2y ago
Except its not. Port forwarding exposes your local environment to the internet, unrestricted. Pinggy (and other sharing platforms - https://github.com/anderspitman/awesome-tunneling ) share a resource on a public IP, wh
75.
▲
by
PLG88
2y ago
If you are going down the open source angle, why not use OSS zero trust auth, starting with OpenZiti - https://openziti.io/ ?
76.
▲
by
PLG88
2y ago
Plenty of alternatives exist - https://github.com/anderspitman/awesome-tunneling . My issue with Funnel is that it includes no auth, exposing you to anyone in the world. I will advocate for zrok.io as I work on its pare
77.
▲
by
PLG88
2y ago
Wow, that looks super useful, thanks!
78.
▲
by
PLG88
2y ago
Evangelising and telling others how awesome zrok and OpenZiti are, that's where you can help the most my friend. Secondary to that, if there is any improvements, or developments that would help you get more value, we love to hear that.
79.
▲
by
PLG88
2y ago
Someone once said to me: At first I tried using Nebula , but provisioning new clients to the network turned out to be not so simple ( https://github.com/slackhq/nebula/issues/479 ). There's a community mai
80.
▲
by
PLG88
2y ago
I love this idea. Personally, I would love to self-host, but don't due to not being technical enough to use a command line. I am from a non-technical background but learnt loads of technical stuff over the years, to the extent that I c
81.
▲
by
PLG88
2y ago
zrok would work, OpenZiti (which zrok is built on) is probably a better comparison to Tailscale IMHO. zrok is a 'ziti-native' app which includes functions to replace Ngrok/Cloudflare Tunnels/Tailscale Funnels (i.e., publ
82.
▲
by
PLG88
2y ago
Maybe we are referring to different things when we say 'process'... I am not aware (happy to be educated) of Firezone having SDKs to embed the zero trust overlay running directly in an application, i.e., in the app process and mem
83.
▲
by
PLG88
2y ago
Yes, indeed, this blog gives a great view on it - https://blog.openziti.io/go-is-amazing-for-zero-trust - using Golang and HTTP examples. My favourite part: " Now, your server has no listening ports on the underlay net
84.
▲
by
PLG88
2y ago
p.s., app embedded makes network attacks almost impossible as you no longer have a listening port on the underlay network, well described here - https://blog.openziti.io/go-is-amazing-for-zero-trust
85.
▲
by
PLG88
2y ago
I cannot speak for Zscaler in this scenario, but I can explain why its different and reduced risk for OpenZiti/NetFoundry (I literally posted on this topic yesterday on LN, blog post coming soon - https://www.linkedin.com&#x
86.
▲
by
PLG88
2y ago
The gateway/ELB has inbound ports and 'listens' on the WAN interface for incoming connections. Therefore it can be subject to external network attacks, and be compromised if a CVE etc exists. Zscaler Private Access makes outb
87.
▲
by
PLG88
2y ago
Ahh, thats cool. Note, the app embedded capabilities of OpenZiti becomes very interesting in this scenario, for example, our Python SDK working with Boto3 for AWS S3 - https://blog.openziti.io/extend-access-to-a-private-s3-b
88.
▲
by
PLG88
2y ago
You could use OpenZiti together with Cilium/Calico, there are some distros, eg., https://kubezt.com/ which do that (though in truth, KubeZT has moved to Istio for E-W, uses OpenZiti for N-S. OpenZiti does a lot of thin
89.
▲
by
PLG88
2y ago
The biggest installation is a cyber security unicorn who whitelabels the commercial version of OpenZiti (NetFoundry) which they are selling to many large enterprises. They have hundreds of thousands of endpoints deployed. There is also a ma
90.
▲
by
PLG88
2y ago
The idea of “zero trust appliances” is that you can reduce the attack surface from the external network, that is how Zscaler positions it, to make you apps 'dark'. IMHO though, the logical conclusion is to give every application,
More ›