this post was submitted on 09 Jun 2025
741 points (98.6% liked)

Selfhosted

49434 readers
878 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Corporate VPN startup Tailscale secures $230 million CAD Series C on back of “surprising” growth

Pennarun confirmed the company had been approached by potential acquirers, but told BetaKit that the company intends to grow as a private company and work towards an initial public offering (IPO).

“Tailscale intends to remain independent and we are on a likely IPO track, although any IPO is several years out,” Pennarun said. “Meanwhile, we have an extremely efficient business model, rapid revenue acceleration, and a long runway that allows us to become profitable when needed, which means we can weather all kinds of economic storms.”

Keep that in mind as you ponder whether and when to switch to self-hosting Headscale.

(page 2) 50 comments
sorted by: hot top controversial new old
[–] deur@feddit.nl 9 points 1 month ago (1 children)

I've realized how easy it is to just actually run a network rather than half ass it with tailscale. I recommend this, it's fun.

load more comments (1 replies)
[–] chameleon@fedia.io 9 points 1 month ago (4 children)

They also had a major ass security issue that a security company should not be able to get away with the other day: assuming everyone with access to an email domain trusts each other unless it's a known-to-them freemail address. And it was by design "to reduce friction".

I don't think a security company where an intentional decision like that can pass through design, development and review can make security products that are fit for purpose. This extends to their published client tooling as used by Headscale, and to some extent the Headscale maintainer hours contributed by Tailscale (which are significant and probably also the first thing to go if the company falls down the usual IPO enshittification).

[–] surph_ninja@lemmy.world 7 points 1 month ago

Isn’t that the entire design philosophy of tailscale?: reduce friction, at the cost of some security.

If security is your main priority, you should be using more secure options, even if they are less convenient or tougher to maintain.

load more comments (3 replies)
[–] ohshit604@sh.itjust.works 6 points 1 month ago* (last edited 1 month ago)

So glad my router supports WireGuard/OVPN server hosting, doing it this way also relieves resources off your homelab and for whatever reason your homelab shuts off or loses network access you can at least rely on your router to re-establish the VPN server without further intervention.

[–] dieTasse@feddit.org 5 points 1 month ago (1 children)

Question: if I setup Headscale on my network, I would have to open a port on my router to connect to it right? And also if I setup Headscale with some cloud provider, could they theoretically go and use the setup to get to my home network? I know its unlikely, I just mean if the technology is like e2e from clients to my home network, or if the cloud headscale 'centre' would be also an unguarded entry point (from the perspective of cloud admins). I hope I am clear 😀 Thanks (btw you probably guess why I currently use Tailscale 😀)

[–] avidamoeba@lemmy.ca 6 points 1 month ago* (last edited 1 month ago) (1 children)

if I setup Headscale on my network, I would have to open a port on my router to connect to it right?

The way I understand it is:

I would have to open a port on my router to connect to it right?

Yes

if I setup Headscale with some cloud provider, could they theoretically go and use the setup to get to my home network?

If they are able to authorize their own node to your Headscale server, then their node gets on your network. If they take over the Headscale node, they might also be able to access your network, either by changing Headscale's config to auth another node or perhaps if the Headscale node is part of the network, which it might be, I don't recall. But I think that's immaterial. If someone takes over the Headscale machine, they can get on your network either way.

load more comments (1 replies)
[–] gravitywell@lemmy.ml 5 points 1 month ago (16 children)

Just use normal wireguard, why do you need tails or heads at all?

load more comments (16 replies)
[–] LiveLM@lemmy.zip 5 points 1 month ago

I always knew it was too nice to stay non-shitty forever.
Guess it's time for me to pester my ISP to let me open some ports

[–] Mordikan@kbin.earth 5 points 1 month ago (9 children)

Headscale is great if you like networking fun, but that aside I'm not understanding why VC funding is such a black mark to the poster. Tailscale doesn't generate meaningful revenue streams as its early-stage, so it has to secure funding to continue operations until they achieve high enough revenue to go public. That's pretty standard in a business life-cycle, though. It seems like the main complaint is that Tailscale is a business. And what about the Linux Foundation? They are funded through private equity. Should you consider switching away because of that?

[–] Feyd@programming.dev 9 points 1 month ago

Not that it is a business but is a specific kind of business. VC funded startups eyeing an IPO more often than not start doing things users are not happy with. Maybe tailscale won't, but might as well be aware what kind of company they are acknowledge there is a decent chance of rugpulls

[–] tequinhu@lemmy.world 8 points 1 month ago (19 children)

Yup, I don't know if that is OP's intention, but I would agree myself with the complaint that "Tailscale is a business"

The way I see it, if it's a business it must generate revenue (either now or down the road), and that is enough to have me worried. I do have a Tailscale registration, and the way they approach email communication is already a yellow flag to me (too many ad emails)

[–] irmadlad@lemmy.world 5 points 1 month ago (2 children)

yellow flag to me (too many ad emails)

Weird. I'm not saying you're lying, but besides the registration email, and onboarding welcome email, I can't think of any others I've received from Tailscale. In fact, I just did a search of my email client, and those were the only ones I've received.

load more comments (2 replies)
load more comments (18 replies)
[–] Ulrich@feddit.org 6 points 1 month ago* (last edited 1 month ago) (7 children)

That's pretty standard in a business life-cycle, though

I don't know where people ever got the idea that normal = acceptable. I hear this used to justify all sorts of awful crap. It was only ever normalized because users were apathetic.

And what about the Linux Foundation? They are funded through private equity. Should you consider switching away because of that?

Does The Linux Foundation have complete control over Linux?

load more comments (7 replies)
load more comments (6 replies)
load more comments
view more: ‹ prev next ›