Comment by jjordan
15 days ago
Probably the most refreshing thing I've read in a while. Glad to support them moving forward if this is indeed their modus operandi.
15 days ago
Probably the most refreshing thing I've read in a while. Glad to support them moving forward if this is indeed their modus operandi.
Tailscale is the best. It's infinitely better than Hamachi, ZeroTier, etc. My only gripe is that they have some really weird SSO requirements like GitHub, etc. and then that provider becomes a permanent part of your identity.
I've been a fan of Tailscale since encountering it for the first time at a previous job at a small startup. Someone asked if anyone had a Linux machine when we were all testing out something, and I mentioned I had a personal Linux desktop but wasn't sure how to connect it to the VPN for access, and it turned out that the solution was just literally running two commands in the terminal after installing tailscale from the repos. Compared to my first job where connecting to the VPN from Linux required hours of mucking around with openswan (or was it strongswan? so many swans...) and trial and error with various config files, it was unfathomably straightforward.
That strongswan thing is the kind of design HN praises about open protocols by IRC (just the other day...) but in practice is so flexible it can't keep itself upright and it's unusable in practice.
Meanwhile tailscale or wireguard, by being actually opinionated, avoids needing much configuration at both ends.
2 replies →
With a desktop its usually possible from the network setting GUI? Worked like that last time I needed to use a VPN for access to a corporate network.
4 replies →
Just FYI - with Tailscale you can switch SSO providers by putting in a support ticket. I did it last year and it was a breeze.
Oh, thank you! I might do that.
I think their reasoning on not being an identify provider but acting solely downstream is very clever.
Y? What's wrong with providing username/password authentication
6 replies →
How are the requirements weird? They support any OIDC endpoint whether your own or a vendor’s, and, while uninteresting to HN folks, they also now support passkeys for having no SSO provider at all.
Yeah, I have my Tailscale tied to my Apple account, which just feels weird. I can add a Passkey account to my Tailnet and make it manager, etc., so that’s what I’ve done. The owner is my Apple account, but I actually do everything admin-wise with a Passkey account.
Oh I had no idea they supported Apple. Maybe they didn't back when I signed up? I'm seemingly stuck with GitHub forever now though.
1 reply →