← Back to context

Comment by xingped

10 hours ago

Hey why do you hard code certain android apps to be excluded from Tailscale with split tunneling without giving users any way to disable split tunneling for these apps? It doesn't matter how you think VPN does or does not affect these apps, it's really awful anti-user behavior.

I haven't heard of this behavior before. Could you elaborate or link to some evidence of it?

I think it is the opposite google allows some apps from opting out of VPN.

  • AFAIK any app can opt out of VPN by binding to the wifi/cellphone interface directly, bypassing the OS's routing tables. You need to enable "block connections without VPN" to prevent any leaks.

I don’t trust or want tools from giant for profit corporations because there’s always some bullshit, and usually by the time you figure it out you’re out time or money. Never used Tailscale and this is a perfect example of my policy working. Notice the no response, they know what they’re doing and they don’t care.

Layer 2 VPN is where it’s at anyway. I want to be on my LAN not managing one device or app at a time, I never got the wireguard hype.

  • > Layer 2 VPN is where it’s at anyway. I want to be on my LAN not managing one device or app at a time, I never got the wireguard hype.

    You can do that though? Tailscale can as well. A device can advertise subnets, and can route them through tailscale, so you just need a single node in a LAN.

    • > A device can advertise subnets, and can route them through tailscale

      This is still L3 layer though. One the main use case of L2 is proper DHCP propagation and avoid subnet collisions. I do not think that this matters in practices though. Only a limited amount of user facing service require proper L2 emulation (apple TVs ?)

      1 reply →

  • > Notice the no response, they know what they’re doing and they don’t care.

    I was with you in principle until this part. You gave them ~30 minutes before claiming "no answer".