Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alexmensch
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
Twingate – Building the foundation for identity-first network security
(twingate.com)
19 points
by
alexmensch
6y ago
|
2 comments
2.
▲
by
alexmensch
6y ago
Hi Everyone! We launched Twingate on Show HN 6 months ago. Excited to share more about a concept we’re calling “Identity-First Networking” and a bunch of product enhancements & partnerships. While most SaaS applications have already mo
3.
▲
by
alexmensch
6y ago
The most important factor in this decision is maintaining separation of concerns between user authentication (identity provider) and network authorization (Twingate). Since we rely on an identity authority for access, if the user--or an att
4.
▲
by
alexmensch
6y ago
Gotcha. In your example: nothing. We're okay with that. The level of security that results from the setup you described is what we are hoping Twingate will bring to people with convenience and ease of management built-in. I'm alwa
5.
▲
by
alexmensch
6y ago
The client (the Twingate app on the user’s device) actually runs a transparent TCP proxy, so we’re just forwarding TCP payloads to the connector at the other end of the tunnel. This avoids the “TCP meltdown” problem of a TCP-in-TCP connecti
6.
▲
by
alexmensch
6y ago
These are all valid points, and we’re keenly aware that trust is central to our offering. On the subject of trust, I’d love to get your take on my response to hlieberman’s comment as I agree that it’s very important. On the pricing front, o
7.
▲
by
alexmensch
6y ago
Could you clarify a bit on "out of band" in this use case? In principle, if you have a way to access your bastion on a completely private--maybe physically separate / leased line--network, then that's going to be extreme
8.
▲
by
alexmensch
6y ago
Our general approach is to rely on widely-used delegated trust mechanisms (eg. OAuth, SAML, CAs, etc.) and from our perspective the more of that we can do the better, as it helps decentralize control mechanisms and improve overall security.
9.
▲
by
alexmensch
6y ago
This is our very first public launch, and auditing/analytics are next up on our roadmap! Just to be clear, we do not currently and do not plan to intercept any traffic—any client application connections remain encrypted inside of our T
10.
▲
by
alexmensch
6y ago
Hey, great question, and your setup seems very secure, but I’m sure it would be nice to reduce some of the overhead. The right way to support your ephemeral bastion use case with Twingate will ultimately be to use a public API that we plan
11.
▲
by
alexmensch
6y ago
Currently, yes, we’re focused on connecting users with services, but there’s nothing inherent to the underlying technology that prevents us handling service to service communication in the future. This is a common request, and along with a
12.
▲
by
alexmensch
6y ago
Totally! We've seen some nightmare configurations around separating dev/staging/prod environments involving scripts to change /etc/hosts back and forth and some funky VPN configurations. This is such a common use ca
13.
▲
by
alexmensch
6y ago
Good question! At the absolute limit, connectors are CPU-bound, but it's unlikely that you would hit a CPU limit before you exhaust all available file descriptors or network bandwidth unless you're using a very under-powered host.
14.
▲
by
alexmensch
6y ago
There are similarities in the general approach, but the two biggest differences between us and Teleport are: 1) We support native clients on every major platform (Mac, Windows, iOS, Android and Linux support just a few weeks away) which mak
15.
▲
by
alexmensch
6y ago
Thanks! One of the things that we've really focused on is making Twingate super, super easy to deploy. From all of our customers conversations we've found that despite acknowledging that a better approach to remote access is poss
16.
▲
by
alexmensch
6y ago
Hi everyone, I’m one of the cofounders of Twingate. Excited to share with the HN community what we’ve been working on over the last 18 months. Twingate is a modern solution for remote access that replaces your VPN. It’s designed to address
17.
▲
Show HN: Twingate – A modern solution for remote access
(twingate.com)
156 points
by
alexmensch
6y ago
|
48 comments