Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's very easy to run your own WireGuard, and if that's all you want, by all means, do that. A lot of work went into making WireGuard the easiest-to-configure VPN --- it's deceptively sophisticated (the best kind of sophisticated).

Tailscale is also deceptively powerful, and that's why people love it. In particular: getting WireGuard deployed across a whole team with a single source of authentication truth and role-based default-deny ACLs is not, in fact, very easy to do. The massively more common pattern in tech companies with access VPNs is something like OpenVPN, with separately-managed credential stores (that get desynced and lock people out --- or accidentally retain access for separated team members) and default-allow network policy that gives anyone with access to the VPN direct access to Redis, databases, staging instances, and stuff like that.

I don't just like Tailscale. I fucking hate Tailscale for how simple they've made one of the larger problems in corpsec. It's maddening.



That's true, the ACLs are pretty huge. I've heard about Tailscale almost exclusively in the context of /r/selfhosted, and this post is about the free plan which guided my response. It's not hard to see why this would be useful at my job. Honestly I wish they'd pay for it, OpenVPN is such a pain for my users.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: