Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dave_universetf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
dave_universetf
4y ago
The funnel relays do SNI-based routing to the target machine in your tailnet, and that machine does the TLS termination. We use the initial TLS handshake to route the connection, but after that it's just opaque bytes to us. You can ver
32.
▲
by
dave_universetf
4y ago
Yeah, we're adding people slowly because decentralized authorities like the one that tailnet lock implements can have nasty failure modes, e.g. some bug that prevents any new addition to the tailnet at all and forces manual recovery on
33.
▲
by
dave_universetf
4y ago
(bulletin co-author) Yeah that bit could have been spelled out more. It's a random 64-bit int.
34.
▲
by
dave_universetf
4y ago
You can grab static binary tarballs on https://pkgs.tailscale.com and then run tailscale in userspace mode: https://tailscale.com/kb/1112/userspace-networking/ .
35.
▲
by
dave_universetf
4y ago
If things still aren't behaving, write in to support@tailscale.com and we'll sort you out. It sounds like the corporate setup wants to just push some custom DNS routes for specific suffixes and leave everything else alone, which i
36.
▲
by
dave_universetf
4y ago
It sounds like your corporate tailnet checked the "override local DNS" setting and provided their own default nameservers, so those are the ones that get used. They could also not do that, at which point your LAN resolver would ge
37.
▲
by
dave_universetf
4y ago
Configuring DNS in general was there before, but there are a couple of NextDNS-specific things that went live: automatically using DoH when using NextDNS, setting profiles on a per-device basis so you can vary what things are blocked or not
38.
▲
by
dave_universetf
4y ago
Google doesn't source its definition, but all reputable dictionaries I could find disagree: https://www.merriam-webster.com/dictionary/insecure definition 3, https://dictionary.cambridge.org/dictio
39.
▲
by
dave_universetf
4y ago
A better URL, with context and stuff: https://tailscale.com/blog/introducing-pgproxy/
40.
▲
by
dave_universetf
4y ago
Trust Report seems to be irrelevant to this (from what I can tell from the brochure without being a vanta customer), because it's a way for a company to publish claims about itself. Crucially, nowhere does it say that an independent au
41.
▲
by
dave_universetf
4y ago
This is a restriction of SOC2 itself. SOC2 produces a "restricted use" report, meant for the client company who purchased it, and for limited access by third parties that do business with the client company. AIUI, the intent is to
42.
▲
by
dave_universetf
4y ago
SFTP is a sub-protocol of SSH (technically a "subsystem" in the RFC-speak), which implements features similar to "legacy" FTP. Anyway, our ssh server knows about sftp, so `sftp <host>` should just work.
43.
▲
by
dave_universetf
4y ago
TouchID and related are on the list. Hooking into the existing auth flow was the easiest to get this out the door (and more desirable for some companies who want the audit event in their SSO stack, arguably), vs. figuring out when to nudge
44.
▲
by
dave_universetf
4y ago
Session recording's actually already in the network engine for SSH, we just haven't plumbed the whole "push recordings somewhere and surface them" yet. Soon :)
45.
▲
by
dave_universetf
4y ago
Our epic treatise on how NAT traversal works (in general, not specific to Tailscale) mentions this. IPv6 greatly reduces the amount of pain for p2p connections, but does not eliminate some of the fundamentals (stateful firewall traversal) i
46.
▲
by
dave_universetf
4y ago
And, for example, a company might be interested in a slightly earlier post about using this "ambient authentication" setup for access to Grafana: https://tailscale.com/blog/grafana-auth/
47.
▲
by
dave_universetf
4y ago
Not necessarily. On linux for example, you'll find netfilter firewall rules installed by tailscale that implement strict reverse path filtering, which will ensure that tailscale IPs can only reach your userspace process if they origina
48.
▲
by
dave_universetf
5y ago
It's also built in natively: https://tailscale.com/kb/1103/exit-nodes/
49.
▲
by
dave_universetf
5y ago
All the hoop-jumping I can think of is open-source. https://github.com/tailscale/go has the Go toolchain changes for size reduction (though most get upstreamed), and the rest of the size reduction stuff comes from lazy
50.
▲
by
dave_universetf
5y ago
Tailscale adds a layer of NAT traversal logic on top of regular WireGuard, so in most cases you end up with p2p WireGuard tunnels between your devices, as if the NAT wasn't there. https://tailscale.com/blog/how-nat
51.
▲
by
dave_universetf
5y ago
The stage0 project has a Forth implementation of the middle layers (between the pure hex writer and Mes), but according to the author Forth wasn't as easy for them as straight assembler or Scheme. They say the Forth code is sitting the
52.
▲
by
dave_universetf
5y ago
I did go that far down, and there is a purpose. Reducing the scope of attack to "you must own a fab" is pretty great, honestly. Sure, it won't stop a perfectly placed nation-state from mounting a bespoke attack just for you b
53.
▲
by
dave_universetf
5y ago
It can, see https://tailscale.com/kb/1019/subnets/ . There's more work for us to do for more "automagic" behavior. For example, I want my home desktop to offer proxying to my printer without ha
54.
▲
by
dave_universetf
5y ago
Not yet on resuming downloads. No principled reason, just haven't gotten to it yet. LAN discovery is handled by Tailscale's network engine, a couple layers of abstraction below the file sending. We're going to add some mdns s
55.
▲
by
dave_universetf
5y ago
It's "launched this week" new, yeah. We don't have a way to migrate between auth providers yet, but if you feel strongly you could log out your devices and sign back in with github auth. That'd create a completely n
56.
▲
by
dave_universetf
5y ago
Just tried to do this to reclaim a channel you stole from its community. Your staff greeted me with nothing but silence. Your aim is very clearly to establish a fiefdom, and damn those who get in the way. "And you're, what, a pett
57.
▲
by
dave_universetf
5y ago
It's a pity, because macOS got the general idea right, but seemingly every single particular wrong thereafter. In general, a modern DNS client wants: a set of "default route" resolvers; a set of "DNS routes" that po
58.
▲
by
dave_universetf
5y ago
This is also what we're trying to do in Tailscale (to grab your MagicDNS domain, and whatever corporate split DNS you set, but not anything else). And yeah, on linux, basically systemd-resolved is the only thing that gets this right (w
59.
▲
by
dave_universetf
6y ago
Mostly we optimize at the application layer (e.g. we do lazy on-demand WireGuard tunnel configuration, to minimize how much state sits around idle). We also have a small fork of Go with some space-optimizing changes: https://gith
60.
▲
by
dave_universetf
6y ago
It's a mild tradeoff the post glossed over: if you're handling IPv6 addresses with a zone specifier, the first use of a particular zone specifier will cause an allocation to intern that string. Thankfully, the vast majority of IP-
More ›