Tailscale Funnel ermöglicht das Port-Forwarding bei Mullvad

Vor fast zwei Jahren stellte der VPN-Anbieter Mullvad alle Portweiterleitungen ab. Ist Tailscale Funnel etwa die Lösung für dieses Dilemma?

TARNKAPPE.INFO
AdGuard und Pi-hole per Smartphone verwalten

AdGuard und Pi-hole per Smartphone verwalten. So steuerst du deine Blocklisten und DNS-Einstellungen mobil, sicher und bequem mit den Apps!

TARNKAPPE.INFO

Tailscale funnel will tell the whole world about your service trough the certificate transparency log.

I just discovered this after watching someone from a Russian IP identifying as "scanner.ducks.party" crawling my little test.

I don't think @tailscale makes it clear at all that anything exposed with tailscale funnel is announced to everyone listening thanks to certificate transparency.
A small warning when running tailscale funnel would be in place because I very much did not expect anyone to find my little funnel. And I doubt others do either.

@tannerprynn also noticed this already a while ago and did a bit of scanning to see what people are putting up. And it was mostly Plex and other hobbyist thing. But I think nowadays Tailscale has moved into enterprise so I would guess there is a lot more "interesting" things being exposed.

https://infosec.exchange/@tannerprynn/110690241082273706

#tailscalefunnel #tailscale #psa #securebydefault

tannerprynn (@[email protected])

Tailscale has a feature called Tailscale Funnel that kind of does the opposite of everything else Tailscale does? It exposes nodes directly to the Internet. And all the hostnames are published in CT, so I scanned it #appsec #nmap #tls #tailscale https://tprynn.github.io/2023/07/10/tailscale-funnel-scanning.html

Infosec Exchange
How did I do it?

A containerized pleroma, running in podman(-compose) on opensuse tumbleweed on the rpi4b (4gb ram) was a simple first step that ensured a sandboxed webserver with very few permissions in the host: https://github.com/angristan/docker-pleroma

I'm quite comfortable with linux, container technologies and webhosting, but I was hellbent on not opening ports on my home router/modem.

Enter tailscale funnel! Tailscale would let me both connect to my rpi from anywhere easily using the `tailscale ssh` system, and `funnel`, combined with `MagicDNS` allowed me to serve my activitypub server publicly (with some throughput limitations that I _hope_ I don't reach).

https://tailscale.com/kb/1223/tailscale-funnel/

Cool stuff! Easy to setup! Mostly safe for my home network!

#TailScaleFunnel
GitHub - angristan/docker-pleroma: Docker image for the Pleroma federated social network

Docker image for the Pleroma federated social network - angristan/docker-pleroma

GitHub
@bdimcheff @w8emv

Yup, turned on Tailscale funnel, brought up Honk. Funnel came up very easily once I spent 5 minutes coming to grips with the "tailnet policy file". Like most good Tailscale stuff it's basically magic.

This instance is super temporary in that it has totally the wrong name, and I am not sure of the right name yet.

The honk mission is to work well if it's what you want.
This does not imply the goal is to be what you want.

Honk is super lightweight, especially compared to Mastodon. Single binary, low memory consumption. The terminology is just confusing enough - emus are in the funzone, for instance - to ensure that it will never get mass adoption.

[ #tailscale #TailscaleFunnel #honkiverse ]

Up and running.

honk 0.9.8
Raspberry Pi 4 (8 GB)
Tailscale Funnel (alpha)

This is a temporary setup, which may be taken offline at any time for any reason. (Famous last words.)

cc @tedu
cc @zev
cc @tailscale
cc @w8emv
cc @Raspberry_Pi

#honkiverse
#Tailscale #TailscaleFunnel