Corporate VPN startup Tailscale secures $230 million CAD Series C on back of “surprising” growth

Pennarun confirmed the company had been approached by potential acquirers, but told BetaKit that the company intends to grow as a private company and work towards an initial public offering (IPO).

“Tailscale intends to remain independent and we are on a likely IPO track, although any IPO is several years out,” Pennarun said. “Meanwhile, we have an extremely efficient business model, rapid revenue acceleration, and a long runway that allows us to become profitable when needed, which means we can weather all kinds of economic storms.”

Keep that in mind as you ponder whether and when to switch to self-hosting Headscale.

  • fmstrat@lemmy.nowsci.com
    link
    fedilink
    English
    arrow-up
    55
    arrow-down
    1
    ·
    edit-2
    7 days ago

    Join our Discord server for a chat and community support.

    Sigh…

    And even worse:

    Everything in Tailscale is Open Source, except the GUI clients for proprietary OS (Windows and macOS/iOS), and the control server.

    • Heals@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      14
      ·
      7 days ago

      To be fair, anything the GUI clients do can be done with the CLI which is still open source and on all desktop platforms and headscale is literally their open source control server.

    • Avid Amoeba@lemmy.caOP
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 days ago

      Huh, I actually didn’t know this because I don’t use Windows/macOS/iOS. Somehow completely missed this.

      • fmstrat@lemmy.nowsci.com
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        6 days ago

        Granted this is not Headscale’s fault, they’re just using Tailscale clients. Either way I’m glad I use a roll-your-own Wireguard.

        I and my partner also don’t use those OSs, but it’s more the point of using FOSS when we can.

  • rarbg@lemmy.zip
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    1
    ·
    6 days ago

    Nerds stop recommending corporate crap: challenge: impossible

  • pulsewidth@lemmy.world
    link
    fedilink
    English
    arrow-up
    35
    ·
    7 days ago

    I think I’ll just keep using tailscale until they start enshittifying, and then set up a Headscale instance on a VPS - no need to take this step ahead of time, right?

    I mean, all the people saying they can avoid any issues by doing the above - what’s to stop Tailscale dropping support for Headscale in future if they’re serious about enshitification? Their Linux & Android clients are open source, but not IOS or Windows so they could easily block access for them.

    My point being - I’ll worry when there is something substantial to worry about, til then they can know I’m using like 3 devices and a github account to authenticate. MagicDNS and the reliability of the clients is just too good for me to switch over mild funding concerns.

    • Avid Amoeba@lemmy.caOP
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      7 days ago

      Yeah, as I said, it’s a friendly reminder. I’m personally probably doing it this year. It’s entirely possible that enshittification could come even years from now. It all depends on how their enterprise adoption goes I think. The more money they make there, the longer the individual users are gonna be left unsqueezed.

  • Vanilla_PuddinFudge@infosec.pub
    link
    fedilink
    English
    arrow-up
    29
    ·
    7 days ago

    I just replaced my entire setup with base wireguard as a challenge, easier than I expected it to be, and not hard to mimic tailscale.

    • unit327@lemmy.zip
      link
      fedilink
      English
      arrow-up
      5
      ·
      6 days ago

      If you just have to talk from many devices to the one server sure, but Tailscale sure makes it easy for many to many. Also if a direct connection is impossible (e.g. firewall of china, CGNAT etc) tailscale puts a relay server in the middle for you.

      • Vanilla_PuddinFudge@infosec.pub
        link
        fedilink
        English
        arrow-up
        3
        ·
        6 days ago

        My entire setup might not be your entire setup, I have the basic functionality of connecting multiple systems into one mesh network. That’s all I needed so it’s all I did.

      • Vanilla_PuddinFudge@infosec.pub
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 days ago

        Pihole and pivpn get along like peas and carrots.

        Make the “available ips” your pivpn subnet and ta-da, the mesh functionality of tailscale without the entire connection.

        Want to exit node from the server? Just change the value back to 0.0.0.0/0.

  • PumaStoleMyBluff@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    6 days ago

    become profitable when needed

    By what, laying off all QA and support staff and half your developers the moment a single quarterly earnings report isn’t spotlessly gilded?

  • Vinstaal0@feddit.nl
    link
    fedilink
    English
    arrow-up
    18
    ·
    6 days ago

    Crap, I really need to switch of Tailscale but currently it is an easy way for me to access my stuff outside of home as a temporary solution while I am on a 5G modem.

      • unit327@lemmy.zip
        link
        fedilink
        English
        arrow-up
        8
        ·
        6 days ago

        I can’t. I tried it first and installed it on my phone from f-droid. After opening it up, it connected to an already existing network with other people’s old machines from years ago on it. I was horrified.

        So then I tried to delete my whole account and couldn’t due to an error. I sent them an email about it and they took like two weeks to respond.

            • Possibly linux@lemmy.zip
              link
              fedilink
              English
              arrow-up
              3
              ·
              6 days ago

              It has never been on F-droid. I’ve been following the service since it started. It didn’t even have a mobile app not that long ago.

              • unit327@lemmy.zip
                link
                fedilink
                English
                arrow-up
                1
                ·
                4 days ago

                It’s possible I misremembered and got the apk from their website or github. Doesn’t change anything though.

                I just went back though my emails, I got a reply email from their CTO promising to look into it and they would get back to me, but they never did.

        • lagoon8622@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          edit-2
          5 days ago

          Crockford is a good and smart person but he really dropped the fucking ball on JSON.

          Double-quotes-only and no comments kill the whole spec for me. Extremely opinionated and dumb. I fucking hate JSON.

          My boss once sent me a machine generated config. He’s terminally addicted to double-quotes (like, a fatal condition). I searched and there were 27k sequences of \".

          Edit: my point is - all that compute and network wasted, every single time the file is requested and parsed. Completely pointless waste

    • natch@lemmy.today
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 days ago

      Do you pay for a domain? They likely provide dynamic DNS (DNS). If you’re lucky, they have an API for it, instead of an app, and you can configure a cronjob on your home server to run every 1-5 minutes (or more often, if your IP is super unstable!).

      • Vinstaal0@feddit.nl
        link
        fedilink
        English
        arrow-up
        3
        ·
        6 days ago

        Yeah I can always do that, but putting stuff behind something like Tailscale is (or atleast feels) more secure than making my IP known to the public. I have a DMZ setup though so it should be fine.

        • chronicledmonocle@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          2
          ·
          6 days ago

          Your “IP address” is already public. That’s why an IPv4 address is assigned to you as a “public IP address” and you NAT to a private space. When using IPv6, everything is public.

          The key is to secure everything with access restrictions.

          • Vinstaal0@feddit.nl
            link
            fedilink
            English
            arrow-up
            2
            ·
            6 days ago

            Well yes I know, but there is a difference between using a domain bound to me as a person and a random string of numbers that changes every 5 minutes

              • Andres@social.ridetrans.it
                link
                fedilink
                arrow-up
                3
                ·
                edit-2
                6 days ago

                @chronicledmonocle @Vinstaal0 I used to work for a dial-up ISP. Every IP is registered to an account, if you’re going through your ISP (as opposed to, say, coffee shop or hotel wifi). Though the people who have the information are different (ICANN/registrar vs your internet provider), there’s no anonymity in your home IP address even with CGNAT.

                As far as your domain, you should have privacy protection enabled so people can’t find your personal info via whois.

              • Vinstaal0@feddit.nl
                link
                fedilink
                English
                arrow-up
                1
                ·
                6 days ago

                That was the case when I lived with my parents, but now it changes every 5 minutes sadly.

                So I had to shut down my Minecraft server etc for now because I am on a 5G modem which makes it really annoying to open up ports and point a domain to your IP

                • LoudWaterHombre@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  5 days ago

                  If your IP changed every 5 minutes, you would not be able to have a voice call or anything similar. Your IP probably changes every 24 hours

  • cooopsspace@infosec.pub
    link
    fedilink
    English
    arrow-up
    25
    ·
    edit-2
    7 days ago

    Friendly reminder that Tailscale is VC-funded and driving towards IPO

    You know what’s to come.

    The answer to the question is immediately. Or switch to OpenZiti or Pangolin even.

    • phx@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 days ago

      Used to run OpenVPN. Tried Wireguard and the performance was much better, although lacking some of the features some might need/want fit credential-based logins etc

      • _TheLoneDeveloper_@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        3
        ·
        5 days ago

        I can highly recommend Netbird selfhosted, it has SSO support, logins, complex network topologies, it uses wireguard under the hood and it’s open source.

        • phx@lemmy.ca
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 days ago

          That sounds kinda cool. I’ll have to check it out. It’s kinda hard sometimes to push FOSS stuff in a largercorporate environment but this looks like something I could recommend/build for small-mid private SOHO clients.

          • _TheLoneDeveloper_@sopuli.xyz
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            This is what I used in a small/mid sized company to replace a legacy VPN, generally we had only very few issues but probably the employee personal computer is to blame, right now is very stable.

      • ipkpjersi@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 days ago

        Yeah, OpenVPN definitely doesn’t have light spec requirements 😅 thankfully hardware is unfathomably powerful these days.

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    edit-2
    7 days ago

    I’m not that worried as there are alternatives like Netbird. The underlying tech really isn’t hard to replicate since Wireguard is pretty standard.

    I think it would be cool if Tailscale made it into the enterprise arena.

    • Avid Amoeba@lemmy.caOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      7 days ago

      I think it would be cool if Tailscale made it into the enterprise arena.

      I think they already have started. Telus is on their list of clients.

  • dabe@lemmy.zip
    link
    fedilink
    English
    arrow-up
    16
    ·
    edit-2
    7 days ago

    Am I totally off-base in thinking that MagicDNS and pluggable DNS nameserver overrides are a huge feature of tailscale?

    I love that I can refer to my tailnet devices just via their machine name. I use it everywhere. And also that I can just slot in my NextDNS ID so that any device running tailscale now automatically uses that, and I don’t have to mess with my shared router settings or per device settings. Is all that actually really easy to set up outside of tailscale? Cuz if it is and I just somehow missed that when doing all my research, I’ll happily give plain wireguard or other mesh orchestrators like NetBird a go.

    And I already know that mDNS is not the answer. That protocol is simply not reliable enough.

    • null_dot@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      7 days ago

      I use wireguard and have public DNS refer to private IPs.

      For example if my server is accessible at 10.0.0.1 via wireguard then I point *.myserver.mydomain.com to that IP.

      Sorry if I’ve misunderstood your question.

    • Avid Amoeba@lemmy.caOP
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      2
      ·
      edit-2
      7 days ago

      Nah, DNS is separate and these features are indeed pretty great. I think Headscale can also do them. I think I tested MagicDNS if I recall correctly.

  • qjkxbmwvz@startrek.website
    link
    fedilink
    English
    arrow-up
    12
    ·
    7 days ago

    I think a lot of companies view their free plan as recruiting/advertising — if you use TailScale personally and have a great experience then you’ll bring in business by advocating for it at work.

    Of course it could go either way, and I don’t rely on TailScale (it’s my “backup” VPN to my home network)… we’ll see, I guess.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      It also doesn’t cost them much of anything

      Positive PR and little draw backs means that everyone is generally pretty happy

  • bonsai@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    5
    ·
    6 days ago

    I never really understood the point of using Tailscale over plain ol’ WireGuard. I mean I guess if youve got a dozen+ nodes but I feel like most laymens topologies won’t be complex beyond a regular old wireguard config

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      edit-2
      6 days ago

      Wireguard doesn’t do NAT/Firewall traversal nor does it have SSO

      Tailscale manages the underlying Wireguard for you. I would be great if Wireguard had native NAT traversal but that isn’t the case.

    • Jason2357@lemmy.ca
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      6 days ago

      NAT punching and proxying when a p2p connection between any 2 nodes cannot be achieved. It’s a world of difference with mobile devices when they always see each other, all the time. However, headscale does all that.

      • bonsai@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        5
        ·
        6 days ago

        I mean sure, but I don’t think it’s simpler than setting up a wireguard config IMO. For tailscale you gotta make an account, register devices, connect them. Feel like wireguard is about the same except you don’t have to make an account.

    • _TheLoneDeveloper_@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 days ago

      Same thing here, either tailscale selfhosted or Netbird selfhosted I’d the way to go for all the nice features, having the free tier or tailscale for personal data never sounded right to me.

  • ohshit604@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    7 days ago

    So glad my router supports WireGuard/OVPN server hosting, doing it this way also relieves resources off your homelab and for whatever reason your homelab shuts off or loses network access you can at least rely on your router to re-establish the VPN server without further intervention.