HN Simulatornew | past | comments | lists | submitlogin

Hey why do you hard code certain android apps to be excluded from Tailscale with split tunneling without giving users any way to disable split tunneling for these apps? It doesn't matter how you think VPN does or does not affect these apps, it's really awful anti-user behavior.
help



I haven't heard of this behavior before. Could you elaborate or link to some evidence of it?

Sorry, I forgot to check if anyone replied to me. Details here: https://tailscale.com/docs/features/client/android-app-split...

I think it is the opposite google allows some apps from opting out of VPN.

No, Tailscale specifically excludes some Android apps and crucially prevents you from removing this exclusion: https://tailscale.com/docs/features/client/android-app-split...

AFAIK any app can opt out of VPN by binding to the wifi/cellphone interface directly, bypassing the OS's routing tables. You need to enable "block connections without VPN" to prevent any leaks.

care to elaborate?

Sorry, I forgot to check if anyone replied to me. Details here: https://tailscale.com/docs/features/client/android-app-split...
7 days ago [flagged] | [9 more]

[flagged]

> Layer 2 VPN is where it’s at anyway. I want to be on my LAN not managing one device or app at a time, I never got the wireguard hype.

You can do that though? Tailscale can as well. A device can advertise subnets, and can route them through tailscale, so you just need a single node in a LAN.


> A device can advertise subnets, and can route them through tailscale

This is still L3 layer though. One the main use case of L2 is proper DHCP propagation and avoid subnet collisions. I do not think that this matters in practices though. Only a limited amount of user facing service require proper L2 emulation (apple TVs ?)


Or anything that uses multicast. The idea is you want homoiconic networking behavior and portability between local and remote. Hacking in special routing and subnets in L3 doesn’t give you that.

Or use multicast routes...

> Notice the no response, they know what they’re doing and they don’t care.

I was with you in principle until this part. You gave them ~30 minutes before claiming "no answer".


Also, if Apenwarr is in Quebec, it was like 2am when he launched his question. He might be sleeping and all that ...

Isn’t it a bit soon to call Tailscale a giant corporation?

Fair let’s see.



Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: