←back to thread

Tailscale raises $100M

(tailscale.com)
854 points gmemstr | 1 comments | | HN request time: 0.424s | source
Show context
aaronax ◴[] No.31260498[source]
I have heard of but never really looked in to Tailscale until today. I'm not impressed.

"Fixing the Internet" is not done by layering more private network garbage on top of it.

Their claim[0] that after you install Tailscale on all your devices: "This final configuration is called 'zero trust networking',” is pretty interesting. It seems this would be more like having a trusted internal network (sure it is overlaid on an untrusted network). A true zero-trust network would mean all of your clients and servers are secure in a manner that they can operate on the public Internet...like O365, Salesforce, etc. To say that you run a zero-trust network because you implement a fancy VPN is C-suite dreaming at its finest.

"get around a misbehaving corporate firewall" like newhouseb sings praises for is exactly the sort of thing that should be happening less, and the opposite of "fixing the Internet". Follow the policies of the network you are being allowed to use, or lobby for them the be fixed. Don't like ISPs messing with DNS traffic? Get rules/laws implemented that prohibit that, instead of garbage like hiding your DNS in DNS over HTTPS. (DNS over TLS seems more acceptable to me.)

[0] https://tailscale.com/blog/how-tailscale-works/

replies(3): >>31260551 #>>31260560 #>>31260730 #
1. newhouseb ◴[] No.31260730[source]
To be fair, my "misbehaving corporate firewall" is actually my apartment that has building-managed internet wherein everyone is NAT'ed to the same fiber connection.

For whatever reason, SYN flooding detection triggers when you do more than a few TCP connections per second which makes most TCP-based things super frustrating and their IT is clueless as to how to fix it.