> - Tailscale so me, my family and friends
If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network: https://tailscale.com/docs/features/logging
“This includes real-time events for open and close events for every inter-machine connection (TCP or UDP) on your network.”
https://tailscale.com/docs/features/logging#opt-out-of-clien...
Yeah for sure, but good luck getting mom and dad to edit `%PROGRAMDATA%\Tailscale\tailscaled-env.txt` at all, much less do so correctly.
o no, they’re seeing open and close events between my laptop and my vps and database. the fbi will surely bring the hammer down on me
Why don’t people just use Wireguard?
Once you get to N = >10 devices, and expect some degree of decentralized communication between them you find yourself maintaining N^2 entries. Every change to the set of public keys, require you updating N entries. Things get worse once you want consistent rules on what-device-should-access-what.
I initially used WireGuard, but as my home lab scaled, it became unwieldy. Some people could work around these limitations with bash scripts, but if you have an heterogeneous environment (esp iOS clients), making programmatic configuration changes to WireGuard becomes trickier.
Today I use Tailscale (with Headscale as the control plane) for all users, and WireGuard as a emergency access to key servers.
Does headscale fully replace the corporate tailscale network? I've been looking at replacing my home wireguard if I can self-host tailscale but haven't had the free time to really figure out how much privacy I can retain by using headscale.
It definitely can. By default it ships with the normal Tailscale DERP map but it also ships with a default-off DERP server. You can turn that on and set your DERP map to only include that one server (or you can fan out a couple if you want). At that point you're not using Tailscale assets at all.
Thanks! Once I have some more time this winter I will take a look at using this to replace my wireguard setup.
For much the same reason most people choose Windows or Mac over Gentoo. Most people set up something like Tailscale to accomplish something rather than create a project and ongoing maintenance burden for themselves, and setting up Wireguard is not terribly friendly to the uninitiated.
WireGuard is one of the easiest things to set up. The total amount of reading you'd need to do to set up WireGuard amounts to half of a page. I spent more time figuring out what firewall rules are needed for WireGuard traffic than actually setting up WireGuard, it's so simple.
I'm going to disagree with you there. It's been a while since I set up anything with WireGuard but "easy" is not a word I would apply to it. A simple tunnel or VPN configuration was close to that but a network comparable to a Tailnet got pretty involved to do properly. By contrast Tailscale was effortless.
Needing to do additional things like figure out firewall rules is exactly what I'm talking about. I enjoy tinkering for fun most of the time but I'm generally looking to tinker on something specific, not every step along the way.
AI has mostly removed the difficulty of Linux configuration for beginners
It's also removed the difficulty of configuring a mikrotik router as well. Mikrotik has a cloud router instance which is much easier to deal with I think than linux. Mostly because there's a UI interface for Mikrotik that makes it a little easier to inspect what's going on.
One of my pet projects I need to get back to is an SDN to make configuration for mikrotik routers easier (particularly with VLAN's, wireguard or VPNS, or routing configuration between ports).
Winbox is nice in a sense because it tells you the true configuration. But what I really want is something that can start with a network diagram (e.g.) and then get the current state of the router, and then validate that against the network config.
How does wireguard helps you with NAT traversal? Reliable NAT traversal on top of wireguard is their moat.
> Reliable NAT traversal on top of wireguard is their moat
And a damned good one at that. I can spend five minutes on a (family) nontechnical user's device and set it up to be able to access the parts of my network it needs to get to, and it's easy enough to use that I can walk them through the troubleshooting over the phone if it ever goes awry. Regardless of where they are or I am.
> How does wireguard helps you with NAT traversal?
It does not. You need a public endpoint, but presumably the $5 VPS or the "homelab" provides that, or it's of little use for things like email, Web, or game servers.
This. Wireguard is a single short text file with keys. It's simple and robust, and setting it up on a client like a laptop or a phone is equally easy. Tailscale or Headscale (the self-hosted version) are massively overengineered for something as basic as accessing your Linux ISOs from your phone.
I'll argue though that the convenience and autonomic management make a big difference in that case because if your Wireguard configuration is busted you might need a working Wireguard to log into your homelab and fix it.
Of course the default behavior that Tailscale forces you to reauthenticate periodically can cause the same problem unless... you turn it off. You know things like that always happen at the worst time.
It’s also entirely impossible to use by itself when both devices you’re trying to connect are behind a NAT or some other restricted network.
That's true, but the $5 VPS should have a public IP, either v4 or v6. Other devices can route their traffic through it, and then every device can reach other devices, regardless of NAT.
It better have v4 if you ever want to use it while traveling. v6 is still not widely enough available on public Wi-Fi networks and even many mobile operators.
On some OSes you could probably also use some additional 4->6 tunnel, but that probably doesn't work stacked under Wireguard on iOS and Android.
But I'd think at that point there'd be arguments for using that vps to instead facilitate a p2p connection... right?
Yes, but only if the VPS becomes a bottleneck. Otherwise self-hosting Headscale does not seem worth it. My guess is that the threshold is at dozens of devices in simultaneous use.
That’s a bit like telling somebody to take a ship instead of an airplane: A nice idea, but not everybody lives at the sea.
I started with Wireguard first, however the setup / maintenance makes it a way bigger project than simply using Tailscale.
arguably that's the entire point of tailscale -- ain't gotta worry about the logistics
good alternatives that do near the same thing?
Netbird, been using it for about 6 months now with no complaints. Fully OSS, mobile clients, etc.
self-hosted open source alternative Headscale/Headplane. Uses the Tailscale client without their SaaS being involved.
Same! Although, for Headplane you may need at least 1GB of RAM.
Headscale turns the $5 VPS into the thing that connects my laptop to my other compute resources while I am out and about.
What's the advantage of Tailscale anyway? I guess ease of use compared to say setting up IPSEC? I haven't played with it yet but from what I read it's just wireguard with a bit of proprietary "one click and sell your soul" magic around it?
Tailscale automates wireguard key distribution and then layers routing, DNS, network ACLs, and other niceties on top.
For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.
It's a VPN essentially but just works easily and affordably. We don't stress on managing keys, secrets etc and it's SSO friendly.
How do you know their client won't send them the metadata anyway?
It is open source
Sanctum! Entirely free and open-source and PQ-secure.
https://sanctorum.se
tl;dr
> no mobile clients
I’ve no need for them personally so they don’t exist in the official repo.
I know of some people however who hacked up their own using the sanctum library (https://github.com/jorisvink/libkyrka)
That is a bummer.
Netbird has a self hosted option
You can ask an LLM to set up a wireguard network for you with an idempotent bash script to deploy everything. You'll need a $5 VPS to bounce everything through. Works an absolute treat.
Is that the prompt you would use, or is there more to it?
The wireguard docs are pretty good, and it's probably worth it at least a little to actually understand what it does.
https://www.wireguard.com/quickstart/
Actually I wish they would be a lot more verbose and explain the details a little bit better.
Yep and the LLM can help explain, but it is actually super straightforward. Public key cryptography and the text file configs are tiny.
[dead]
You could try with that as a prompt. I have a repo set up with all of my sysadmin scripts and so the LLM had that as additional context.
Netbird!
I saw all the Netbird recs here so looked into it briefly. Depends I guess on what you use Tailscale for. Tailscale Funnel is easy and stable. Self-hosted on Netbird is ... a bit more involved.
Definitely a place for both services, IMO.
i literally do not care about that metadata
Sad
Why? It's TCP/UDP connection data for troubleshooting you can turn off. No privacy issue there.
> connection data for troubleshooting you can turn off. No privacy issue there.
You can't turn off the centralised element of Tailscale though, i.e. IP tracking etc.
So for the privacy conscious Tailscale remains a poor choice. Especially as they operate under US jurisdiction:
So CLOUD, PATRIOT and friends very much apply to Tailscale.You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.
I ran Headscale for a while, and now wireguard directly, but never really considered it to be more private.
What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?
> What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?
Tons more. A lot could be written about, but a few "for starters" things to think about:
Yes, `--no-logs-no-support` exists for the Tailscale client — but that's per-device, per-platform inconsistent (as the docs show), forfeits support, and doesn't change the fact that coordination traffic, the DERP relays, and the control plane still run through Tailscale. You can't opt out of the centralized control plane at all.I think you are overestimating how decentralized the web is. Tailscale (could) collect a different kind of data than e.g. Google, and I believe it's far less harmful for the average user. If you are a journalist or persecuted by a government then sure, Tailscale is bad news.
But if you think Tailscale is bad for mobile devices because they might be able to tell that you're near another Tailscale user, that is absurd. If you have a need to be physically untrackable, the only solution is to leave your tracking device at home.
> You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.
Like? What exactly could they plausibly do, that I should care about, if I otherwise have no reason to worry about these institutions?
"We kill people based on metadata." - NSA Chief Gen. Michael Hayden, 2014[1]
In case you were not aware, spooks have focused on metadata analysis over "full take" (data) analysis for a very long time because they are far more effective and require less data to analyse. This has been the case at least since the early 2000s with Stellar Wind but arguably even the Stasi worked this way -- they cared a lot more about who you were talking to than what you were talking about. The Snowden revelations in 2013 talked almost entirely about metadata-only systems that were being used to invasively surveil the world.
If your point was more "I have nothing to hide" then you can find plenty of articles online to disabuse you of that notion. There's even a Wikipedia article about it[2].
[1]: https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-... [2]: https://en.wikipedia.org/wiki/Nothing_to_hide_argument
Can you be on the internet and avoid the collection of metadata that can eventually be accessible for the NSA or other TLA? You have an ISP which logs everything, same for your destination endpoint, and those logs are already being correlated.
Can I even hide from NSA level adversaries without employing extreme methods? Assuming "no", then for this particular threat model do the tools employed next matter?
There is some evidence that Tor has posed significant problems for three-letter-agencies in the past, so it's not like there is nothing to be done at all.
But there is a bigger point to be made: in my experience most privacy activists argue that taking an absolutist stance personally is counter-productive -- just because it is almost impossible to completely eliminate risks from your life does not mean you should give up and not try to minimise them. And of course, the goal for most people isn't to protect against targeted attacks (since that means you already need to take fugitive-on-the-run-level precautions), it's to avoid becoming a target in the first place.
Most privacy activists are already taking an absolutist stance.
Reality is, for normal people there's no point where worrying about spooks and taking actions to protect themselves is reasonable. As you say, there's nothing one can do against a targeted attack. But same is true for broad, untargeted sweeps - if they really care, they will find you anyway, and attempting to reduce your data exposure just flags you as an anomaly, making you more interesting, not less.
The whole "privacy vs spooks" threat analysis is not relevant to regular people.
What I mean to ask was related to the mention made above, that Tailscale shouldn't be used by privacy conscious people.
> If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network
Is Tailscale creating additional metadata that doesn't already exist in "concentrated" form with my ISP? As a regular person trying to live a normal "internet enabled" life (self hosting a few things, sharing things with family or friends....) are there alternatives to Tailscale that leave substantially fewer traces for "Room 641s" and other similar entities, and doesn't just move the metadata collection to the hosting provider or the ISP?
And finally, does disabling logging in Tailscale mitigate those concerns? After all Tailscale will always be a target for data collection whether they cooperate or not by virtue of where they placed themselves. Similar to Cloudflare probably.
My point is I don't care. It's not a thing worth caring about.
I don't argue "I have nothing to hide", even uttering this phrase is giving in to privacy paranoia.
In reality, I have plenty to hide. But those who I want to hide it from, don't have access to the metadata you mention - and those who do have access, couldn't give less of a damn about the things I want to hide.
That's a really uncharitable take. Yes there's client logging by default, but those who are privacy conscious probably also continued to read the very next few sentences in the same section of the docs you quoted, showing precisely how to opt out.