Hacker News new | ask | show | jobs
by X-Cubed 1543 days ago
There are alternative solutions available for those that don't like the Tailscale authentication model, including using Wireguard directly.

Tailscale does not need to be all things to all people, and especially not at the free tier for personal use. Adding extra complexity to the product would mean that it would no longer be the easy to use tool that it currently is.

2 comments

Agree, and by leveraging other common IDPs, they take themselves out of the high touch account management tasks for that tier.
It's funny how you think Google does high-touch account management.
It's maybe clearer to say, Google enables any company's Google Workspace administrator to do high-touch account management, and/or to set up tricky things with accounts.

There's BeyondCorp; there's two-way SAML directory binding (i.e. Google can be your enterprise's IdP for other service, or you can use your enterprise's IdP to sign into Google!); there's GCP Application Default Credentials; MFA device bindings; "application passwords" to pass through 2FA requirements; the ability to tell the auth layer to temporarily disable a user's password prompts via the admin dashboard; Google Take-out; Workspace account data export for terminated users; detachable adjunct accounts (e.g. Youtube channels); etc x1000.

Did you know that tucked away within every Google account is a set of AWS-looking credentials, that exist only to allow object-storage clients that only speak the de-facto "S3-compatible" object-storage API, to interact with Google Cloud Storage, authed as a given user? That's the kind of thing that using Google as your IdP gets you.

Github, meanwhile... if you're not using Github Enterprise, you can't even sync team memberships from your enterprise directory, so you have to grant your HR people org admin(!) access, so that they can grant and revoke team memberships during employee onboarding/offboarding.

can you tell me more about how to get these “s3” keys
https://console.cloud.google.com/storage/settings;tab=intero..., at the bottom — "Access keys for your user account".
thanks!!!
Nebula from slack, but very beta.