Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bradfitz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
151.
▲
by
bradfitz
4y ago
We want other forms too. More will come.
152.
▲
by
bradfitz
4y ago
And 40% * 40% = 16% if you're doing P2P. IPv6 is an option, but not the one true answer (yet?). It helps sometimes. For Tailscale, IPv6 helps about 7% of the time to bust a NAT connection.
153.
▲
by
bradfitz
4y ago
We love IPv6 at Tailscale! It's just not pervasive yet, so we do what we gotta do.
154.
▲
by
bradfitz
4y ago
Our Funnel ingress servers won't proxy any TCP connection that doesn't have a *.ts.net SNI name currently. But BYODomain is something that'd be fun to add.
155.
▲
by
bradfitz
4y ago
Author here. This shouldn't preclude doing us Encrypted ClientHello in the future. We control the DNS for *.ts.net so we can publish our public key for browsers/etc to encrypt the ClientHello to, if I'm remembering the latest
156.
▲
by
bradfitz
4y ago
Author here. We might do BYODomain later. It was easier to launch with only *.ts.net. If you're using this for things like webhooks, the URL doesn't matter much.
157.
▲
by
bradfitz
4y ago
Because Apple went to use that API and hit that restriction themselves for the first time when they shipped Apple Private Relay and found it was too tight.
158.
▲
by
bradfitz
4y ago
But Go used to implement some things with self modifying code. iOS (and OpenBSD) with their W^X restrictions are largely why Go changed.
159.
▲
by
bradfitz
4y ago
Which blog post are you referring to? But yes, we love Fly and use them (and they use us) and we share a slack channel between our two companies for casual banter.
160.
▲
by
bradfitz
4y ago
> Also, why not compile VNC into WASM and get full remote desktop experience for graphical apps. It seems that hard work has already been done! Yup. :) In fact, that's mentioned in the original public bug: https://github.
161.
▲
by
bradfitz
4y ago
> Having an SSH client in your browser join your VPN violates all the principles of modern computing. I think that's a compliment? You're welcome? :)
162.
▲
by
bradfitz
4y ago
Most of the Split DNS issues should be fixed now. If you're on Linux, you want systemd-resolved, as it's the only Linux DNS resolver that's really any good, regardless of your opinions on systemd overall (See https:/&#x
163.
▲
by
bradfitz
4y ago
Couple reasons. 1. We want you to be able to get HTTPS certs for these too without having to manage multiple names, but HTTPS cert names go on the CT log. See https://tailscale.com/blog/tls-certs/ and https:/
164.
▲
by
bradfitz
4y ago
(Tailscale engineer here) What's the bug? I hadn't heard about this. Metrics show no drop in iOS control plane connections.
165.
▲
by
bradfitz
4y ago
No different than the interaction between MagicDNS & any other upstream DNS (Google, Cloudflare, your own, etc). The built-in resolver at 100.100.100.100 handles the *.your-tailscale-suffix names in your tailnet and the rest that doesn&
166.
▲
by
bradfitz
4y ago
Sounds like maybe you entered your NextDNS IPv4 address instead of just the IPv6? (UI improvements there coming soon.) We only ask for the v6 to get the config profile out of it but actually use either address family to DoH as needed.
167.
▲
by
bradfitz
4y ago
Yes. The DNS bootstrap phase is annoying and complicated though. Currently we only do DoH for the big public DNS providers that have well known anycast IPs for their DoH endpoints. That means there's no bootstrap needed.
168.
▲
by
bradfitz
4y ago
There was engineering work on both sides for us to launch this. I did much of the Tailscale side. https://github.com/tailscale/tailscale/issues/2452 links to all the client commits. There was also a lot of co
169.
▲
by
bradfitz
4y ago
Author here. What's new is that your NextDNS configuration profile is preserved even if your client can't do IPv6. We did DNS-over-HTTPs previously for the big public DNS providers, but now we also do DoH for NextDNS, using IPv4 o
170.
▲
by
bradfitz
4y ago
Sorry, author here. It got edited down a bit for brevity. For one user never leaving your house, you're correct. But once you have two or more users in different cities (or you're traveling), then your Pi at home will almost alway
171.
▲
by
bradfitz
4y ago
Tried it in German. Me: "Wie heißt du?" (What's your name?) It: "Tut mir leid, was?" (Sorry, what?) Not a great first impression.
172.
▲
by
bradfitz
4y ago
I think the parent comment was familiar with that and was asking whether we could also do the same for these fish.
173.
▲
by
bradfitz
4y ago
That happened already, no? https://www.mnot.net/blog/2014/06/07/rfc2616_is_dead
174.
▲
by
bradfitz
4y ago
> I wonder why they don't open source the iOS client like they do Android. Mostly because developing for iOS and macOS is terrible, especially when your app needs to have "entitlements". Tailscale uses a "Network Exte
175.
▲
by
bradfitz
4y ago
https://github.com/tailscale/tailscale/issues/4911 is now fixed and will be in the next release.
176.
▲
by
bradfitz
4y ago
> when tailscale ssh was a secret binary in the tailscale github repo That makes it sound like we put a binary in our git repo :) It was its own Go package main that people could run. It was never a secret. We just didn't advertise
177.
▲
by
bradfitz
4y ago
I've passed that on to coworkers.
178.
▲
by
bradfitz
4y ago
We successfully tested a number of iOS SSH clients. They should all work. Can you file a bug with details of what you saw? Either https://github.com/tailscale/tailscale/issues/new or email support@ ... which
179.
▲
by
bradfitz
4y ago
The Linux Programming Interface: https://man7.org/tlpi/ Advanced Programming in the UNIX Environment, 3rd Edition: https://www.amazon.com/gp/product/0321637739
180.
▲
by
bradfitz
4y ago
Yes. But so does regular SSH over Tailscale, so Tailscale SSH isn't special in that regard.
More ›