6 ms·
I appreciate the response - great blog post. I don't doubt this works for certain companies and components of the ecosystem; it worked for Dropbox (at least for
by ogaj 3y ago
I appreciate the response - great blog post. I don't doubt this works for certain companies and components of the ecosystem; it worked for Dropbox (at least for a long time).
Tailscale is clearly a superior product to it's competitors and I have regularly recommended colleagues and clients to evaluate whether it fits their needs. However, unfortunately, that is frequently not enough to "win" in the crowded and bureaucratic enterprise software space.
I would love to be proved wrong here and wish you the greatest success!
- Spooky23 3y agoThe big problem with Tailscale in enterprise is it can't touch anything that interacts with lots of compliance domains, which typically require FIPS. There are creative ways to get around that, but it makes implementation a complex story and heavy lift.
- tptacek 3y agoWhich "compliance domains" are you thinking of that require FIPS crypto for access VPNs? Be specific, if you can? Thanks!
- jgalt212 3y ago> Be specific, if you can? Thanks! Too many ChatGPT interactions lately, I suspect.
- Spooky23 3y agoSay you were a county social services department. You wish to use Tailscale to microsegment federal tax data (subject to IRS 1075 safeguards requirements) relating to your child support unit from other traffic (say Medicaid enrollment) which does not have that requirement. I’m pretty confident that you would draw an audit finding for that reason with a pure tailscale solution. (I also think that’s bullshit.)
- tptacek 3y ago1075 does not appear to require that access VPNs use FIPS cryptography. Arguably, it would if you were relying exclusively on WireGuard for data protection, but it's uncommon for people to do that (we're WireGuard true believers and we do in places depend on WireGuard authentication and encryption for our security model, but it's a weird enough thing to do that we notice it when we do it).
- Spooky23 3y agoSee section 4.18, control SC-13.
- tptacek 3y agoYes, I'm familiar. I don't believe that means everything you use that happens to involve cryptography has to comply with that control.
- Spooky23 3y agoAt the time we looked at it for a client, in an audit, certain aspects would be at the discretion of the auditor. They are typically pragmatic about this stuff. That said my original statement was too broad. It’s not an “enterprise” issue, more use case dependent in regulated scenarios.
- redrove 3y agoOf course the typical comment that ignores every other country except the USA.