Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

NAT busting is a plus. Avoid needing DDNS and opening a port. Also easier setup for accessing other stuff on the network via that computer vs up/down rules with a standard wg config.

For a small setup thats the big thing, but for anything a little more it does key rotation, handles ips for you, and offers "magic dns" which makes all the devices get a nice DNS address when tailscale is on.



NAT busting is a minus. If apps can create holes in your network and “bust your NAT,” your network is not well secured; you should disable UPnP and filter egress.

Also, you gain simplicity but give up to coordination servers, that can be a privacy and security problem.



That was an interesting read. Turns out they do use UPnP, but it's just one of many tools they turn to when other techniques fail.


Sidenote: this is a fantastic writeup.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: