As in, would they be able to access your server?

  • Thomas
    link
    fedilink
    471 month ago

    If you do not trust Tailscale as a company, here is an open source re-implementation of the server called headscale. Some/all clients are open source as well. So, you can review all components yourself or pay for a professional third-party review. Otherwise, if you take a binary blob from any origin, including Tailscale, and have it run with privileges on your server, there are few limits on what this blob can do. Yes, backdoors are technically possible, but probably bad for Tailscale’s business if that ever came to light.

    • @jqubed
      link
      61 month ago

      I’ve never heard of professional third-party review of open source code. That’s a service people offer?

      • @[email protected]
        link
        fedilink
        English
        61 month ago

        I’ve heard of it, but I didn’t think it was financially viable for an individual to pay for though.

    • @[email protected]
      link
      fedilink
      41 month ago

      I’ve always wanted to do this however do I understand it correctly that I need to host headscale on a vps server that is not in my tailnet/home network?

      • @[email protected]
        link
        fedilink
        51 month ago

        It can be on your home network, but it needs to be reachable via HTTPS through the internet. So yeah, a vps is probably the best option.

  • @[email protected]
    link
    fedilink
    261 month ago

    From what I understand tailscale is basically wire guard but made convenient. And how they do that is by managing you wire guard keys for you. So I would have assumed they could use the keys to access your network. HOWever while trying to look into this just now I found out tailnet lock exist and it says “When tailnet lock is enabled, even if Tailscale infrastructure is malicious or hacked, attackers can’t send or receive traffic on your tailnet.”

  • a1studmuffin
    link
    fedilink
    English
    111 month ago

    If you’re concerned about privacy I don’t know why you’d use Tailscale over Wireguard directly. The latter is slightly more fiddly to configure, but you only do it once and there’s no cloud middleman involved, just your devices talking directly to each other.

    • TreedrakeOP
      link
      fedilink
      31 month ago

      Yes, fair. I was just attracted by the no-hassle method of Tailscale.

      • @czardestructo
        link
        11 month ago

        Yes and because wiregurad is stateless you’ll need a script that checks if your DNS endpoint has updated and restart the wireguard interface so it pulls the fresh DNS/updated IP address. I had to make said bash script for my nodes.

      • kadotux
        link
        fedilink
        11 month ago

        Nope, just an open port. Works directly with public IP. I guess if some ISPs IP lease time is short and they keep changing it regularly, it might become a hassle.

  • @devfuuu
    link
    61 month ago

    The official service is bound to need a SSO login from bad privacy related providers. They insist in not allowing a simple account creation with just email and password.

    • @milliams
      link
      01 month ago

      You can relatively easily set up a self-hosted OIDC sever like like Keycloak or Kanidm.

  • @[email protected]
    link
    fedilink
    51 month ago

    The biggest downside, as I understand it, is that it’s difficult to convince others to use your tailnet

  • @[email protected]
    link
    fedilink
    21 month ago

    Not a response, but I used to use taikscale with my own headscale server without problems but for some reason it just started to fail (I didn’t even updated tailscake nor headscake at all) and the speeds with direct connection were some unbelievable 0.00Mbps over direct connection.

    I searched for another MeshVPN and I found something called NetMaker, you can Selfhosted it too and it works really well. The speed is better than Taikscale too because it uses kernel wireguard instead of user space. They still lack some features like an Android client but I don’t care. I just want to connect servers securely. It’s pretty new software so it can have some bugs.

  • @MNLFNUT8YG
    link
    21 month ago

    Why not a direct VPN/WireGuard link to your home network? Works flawless.

  • @[email protected]
    link
    fedilink
    English
    0
    edit-2
    1 month ago

    I use zerotier and afaik they can’t access it, hence, I assume it’s the same for tailscale

  • @[email protected]
    link
    fedilink
    -11 month ago

    The WireGuard encryptions stops when data reaches their servers and the data is re-encrypted to be sent to the client. So, theoretically, they can look at all the data being passed through.

    Read more here about TLS termination and TLS passthrough. https://blog.aiquiral.me/bypass-cgnat