> connection data for troubleshooting you can turn off. No privacy issue there.
You can't turn off the centralised element of Tailscale though, i.e. IP tracking etc.
So for the privacy conscious Tailscale remains a poor choice. Especially as they operate under US jurisdiction:
- "Tailscale US Inc., a Delaware corporation with registered address at 447 Sutter St Ste 405 #543, San Francisco, CA 94108, USA"
- "For any dispute not subject to arbitration you and Tailscale agree to submit to the personal and exclusive jurisdiction of and venue in the federal and state courts located in New York, NY".
So CLOUD, PATRIOT and friends very much apply to Tailscale.You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.
I ran Headscale for a while, and now wireguard directly, but never really considered it to be more private.
What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?
> What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?
Tons more. A lot could be written about, but a few "for starters" things to think about:
Yes, `--no-logs-no-support` exists for the Tailscale client — but that's per-device, per-platform inconsistent (as the docs show), forfeits support, and doesn't change the fact that coordination traffic, the DERP relays, and the control plane still run through Tailscale. You can't opt out of the centralized control plane at all.I think you are overestimating how decentralized the web is. Tailscale (could) collect a different kind of data than e.g. Google, and I believe it's far less harmful for the average user. If you are a journalist or persecuted by a government then sure, Tailscale is bad news.
But if you think Tailscale is bad for mobile devices because they might be able to tell that you're near another Tailscale user, that is absurd. If you have a need to be physically untrackable, the only solution is to leave your tracking device at home.
> You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.
Like? What exactly could they plausibly do, that I should care about, if I otherwise have no reason to worry about these institutions?
"We kill people based on metadata." - NSA Chief Gen. Michael Hayden, 2014[1]
In case you were not aware, spooks have focused on metadata analysis over "full take" (data) analysis for a very long time because they are far more effective and require less data to analyse. This has been the case at least since the early 2000s with Stellar Wind but arguably even the Stasi worked this way -- they cared a lot more about who you were talking to than what you were talking about. The Snowden revelations in 2013 talked almost entirely about metadata-only systems that were being used to invasively surveil the world.
If your point was more "I have nothing to hide" then you can find plenty of articles online to disabuse you of that notion. There's even a Wikipedia article about it[2].
[1]: https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-... [2]: https://en.wikipedia.org/wiki/Nothing_to_hide_argument
Can you be on the internet and avoid the collection of metadata that can eventually be accessible for the NSA or other TLA? You have an ISP which logs everything, same for your destination endpoint, and those logs are already being correlated.
Can I even hide from NSA level adversaries without employing extreme methods? Assuming "no", then for this particular threat model do the tools employed next matter?
There is some evidence that Tor has posed significant problems for three-letter-agencies in the past, so it's not like there is nothing to be done at all.
But there is a bigger point to be made: in my experience most privacy activists argue that taking an absolutist stance personally is counter-productive -- just because it is almost impossible to completely eliminate risks from your life does not mean you should give up and not try to minimise them. And of course, the goal for most people isn't to protect against targeted attacks (since that means you already need to take fugitive-on-the-run-level precautions), it's to avoid becoming a target in the first place.
Most privacy activists are already taking an absolutist stance.
Reality is, for normal people there's no point where worrying about spooks and taking actions to protect themselves is reasonable. As you say, there's nothing one can do against a targeted attack. But same is true for broad, untargeted sweeps - if they really care, they will find you anyway, and attempting to reduce your data exposure just flags you as an anomaly, making you more interesting, not less.
The whole "privacy vs spooks" threat analysis is not relevant to regular people.
What I mean to ask was related to the mention made above, that Tailscale shouldn't be used by privacy conscious people.
> If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network
Is Tailscale creating additional metadata that doesn't already exist in "concentrated" form with my ISP? As a regular person trying to live a normal "internet enabled" life (self hosting a few things, sharing things with family or friends....) are there alternatives to Tailscale that leave substantially fewer traces for "Room 641s" and other similar entities, and doesn't just move the metadata collection to the hosting provider or the ISP?
And finally, does disabling logging in Tailscale mitigate those concerns? After all Tailscale will always be a target for data collection whether they cooperate or not by virtue of where they placed themselves. Similar to Cloudflare probably.
My point is I don't care. It's not a thing worth caring about.
I don't argue "I have nothing to hide", even uttering this phrase is giving in to privacy paranoia.
In reality, I have plenty to hide. But those who I want to hide it from, don't have access to the metadata you mention - and those who do have access, couldn't give less of a damn about the things I want to hide.