←back to thread

Tailscale raises $100M

(tailscale.com)
854 points gmemstr | 1 comments | | HN request time: 0.275s | source
Show context
eadmund ◴[] No.31260261[source]
> For people who believe there’s a catch — and most still do — then I don’t know how to write a blog post or hire a marketing or sales team to change their minds.

I think the catch is that (at least at the free level) one must trust an identity providers. For many companies that's probably fair enough, but for high-security companies and private individuals one absolutely cannot trust anything running outside of one's physical control. Service providers can be suborned, either legally by corrupt regimes or illegally by employees. There is no way that I would permit Google, Microsoft or GitHub (their three supported options) to gate access to my private devices.

I think that one must also trust Tailscale themselves, although I could be wrong about that.

replies(3): >>31260411 #>>31260441 #>>31260476 #
lvh ◴[] No.31260441[source]
Tailscale will let you use any SAML or OIDC provider you like in the Enterprise plan (presumably because of the cost of supporting the long tail of nonsense IdPs will produce).

(Disclosure: I'm a (small) investor via Latacora's sibling fund, Lagomorphic.)

replies(3): >>31260700 #>>31262196 #>>31262919 #
typical182 ◴[] No.31260700[source]
Semi-related question: did Latacora or @tqbf ever open source their Go-based SAML IDP: https://twitter.com/tqbf/status/938501701526487040

(That tweet I think was a teaser saying it was coming. I subsequently looked for it a few times and never found it, but maybe plans changed, or maybe I just failed to find it).

replies(1): >>31261529 #
1. lvh ◴[] No.31261529[source]
Nope. It was pretty much just Thomas and Erin working on it, and I don't think it's operational. Sorry :(