frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Security folks, which would you feel more comfortable with?

1•hellosecpeeps•1h ago
Hi all,

I work at a SaaS company that needs to securely connect our cloud control plane to customer on-premise infrastructure in order to run orchestration and automation tasks. We’re trying to avoid requiring customers to open inbound firewall rules or stand up full VPNs.

We’ve narrowed it down to two models: Agent-based HTTPS/mTLS connector

* Customer deploys a small VM/Pod (our agent) inside their environment. * The agent makes an outbound TLS connection (443) to our SaaS, authenticates with mTLS, polls for jobs, and executes them locally. * Simple setup (firewall-friendly, “just outbound HTTPS”), similar to how Datadog agents, GitHub Actions runners, or Terraform Cloud Agents work.

WireGuard-based connector

* Customer deploys the same kind of connector, but instead of plain HTTPS, it establishes a WireGuard tunnel back to our cloud. * Provides a stable overlay /32 per connector, potentially lower latency, and allows us to send jobs and receive results over a secure tunnel. * Requires outbound UDP (or TCP fallback with something like Tailscale/Netbird). * More networking moving parts, but possibly a more robust transport.

We want to balance security posture, customer comfort during security review, and ease of deployment. From your perspective (especially those who review SaaS vendors for security), which approach would give you more confidence, and why?

Thanks!

Comments

NoahZuniga•35m ago
I would use an existing product, maybe something like cloudflare tunnels.
xyzzy123•1m ago
Hi, I have worked on security teams, done supplier assessments and built infrastructure / deployed vendor agents.

Both of these options (assuming best practice configuration) would be acceptable to any security team I've worked on based on the fundamentals. But the limitations of corporate environments and processes mean that one is much easier than the other.

Practically speaking, supplier assessment forms usually have standard paths for TLS, endpoints, settings / ciphers etc. The paperwork is more complicated for WireGuard because there are no "boxes" for it, you have to write out lengthy explanations into spreadsheet cells. It produces a small feeling of discomfort for people filling out and reading form because it does not look "completely standard".

With my deployer hat on - TLS is the happy path. As a deployer, you often don't "own" the network, that's a separate team. These teams (and their equipment) very greatly in their capacity, sometimes they are excellent, sometimes they are dysfunctional. There is usually a standard process or form for "TLS egress to XYZ" - but anything that is NOT this will trigger a complicated workflow requiring actual meetings and people looking at architectures and diagrams etc. You will basically find it "impossible" to deploy into some customer environments if you don't go with TLS, that is the bitter reason why everyone uses it despite other things being "better" along certain dimensions.

Even mTLS or non-public CAs won't work "out of the box" if there is a middlebox that does inspection by terminating and re-establishing the TLS connection. There is usually a ticket / standard process for this - but some customers will need hand-holding through that. That (plus the practical difficulties of terminating it in cloud, which are not so bad in 2025 anymore) is one reason mTLS is not more widely used.

Ask HN: Tomorrow is my first hackathon, any advice?

1•ofou•4m ago•0 comments

Riemannian Geometry and Non-Euclidean Geometry

https://www.preposterousuniverse.com/blog/2015/11/26/thanksgiving-10/
1•programmexxx•5m ago•0 comments

Partijgedrag – A Dutch political voting compass built on public data

https://github.com/van-sprundel/partijgedrag
1•ramon156•7m ago•0 comments

Show HN: Clean metrics for messy coding habits

https://timefly.dev
1•cgonzar3•8m ago•2 comments

Google to merge Android and ChromeOS in 2026

https://www.theregister.com/2025/09/25/google_android_chromeos/
3•fork-bomber•10m ago•0 comments

Does Agentic AI imply output goes to infinity?

https://substack.com/inbox/post/174849090
1•mathattack•10m ago•0 comments

Amygdala–liver signalling orchestrates glycaemic responses to stress

https://www.nature.com/articles/s41586-025-09420-1
2•PaulHoule•12m ago•0 comments

Roblox is shutting down discord clone Guilded.gg

https://devforum.roblox.com/t/update-on-guilded-and-communities/3966775
1•HypomaniaMan•12m ago•0 comments

I have been diving deep into the world of FinOps

https://buttondown.com/apievangelist/archive/weekly-api-evangelist-governance-guidance-9568/
1•mooreds•12m ago•0 comments

The Gameboy emulator that runs everywhere (Terminal, Web, Desktop)

https://github.com/raphamorim/gameboy
1•Bogdanp•13m ago•0 comments

Jax: Fast Combinations Calculation

https://github.com/phoenicyan/combinadics
4•phoenicyan•14m ago•0 comments

East Texas man facing October execution will not seek clemency, his lawyer says

https://www.kltv.com/2025/09/25/east-texas-man-facing-october-execution-will-not-seek-clemency-hi...
1•rossant•14m ago•0 comments

Canoeboot: Free, Libre BIOS/UEFI boot firmware

https://canoeboot.org/
3•jethronethro•17m ago•0 comments

Show HN: National Internet Control Center Minigame

https://claude.ai/public/artifacts/54c8f88e-d9b6-402c-8530-845511766974
1•logicallee•17m ago•0 comments

Trump says US to impose 100% tariff on movies made outside the country

https://www.reuters.com/business/media-telecom/us-impose-100-tariff-movies-made-outside-country-2...
4•voxadam•20m ago•1 comments

What's Happening to Wholesale Electricity Prices?

https://www.construction-physics.com/p/whats-happening-to-wholesale-electricity
2•surprisetalk•20m ago•0 comments

Notes on the Greatest Night in Pop

https://www.ian-leslie.com/p/notes-on-the-greatest-night-in-pop
1•surprisetalk•20m ago•0 comments

Founding Firebase with James Tamplin [video]

https://www.instantdb.com/essays/firebase
1•stopachka•21m ago•0 comments

GOG: The Curse of Monkey Island for 2.39 euros

https://www.gog.com/en/game/the_curse_of_monkey_island
1•doener•22m ago•0 comments

Understanding Cultural Differences: The Michigan Fish Test (2013)

http://michael-roberto.blogspot.com/2013/07/understanding-cultural-differences.html
1•vector_spaces•23m ago•0 comments

AI Antibody Design in 2025

https://blog.booleanbiotech.com/ai-antibody-design-2025
3•harleyk•24m ago•1 comments

China's new K visa beckons foreign tech talent as US hikes H-1B fee

https://www.reuters.com/sustainability/sustainable-finance-reporting/chinas-new-k-visa-beckons-fo...
2•doener•26m ago•0 comments

Startup Founder Charlie Javice Sentenced to over 7 Years for Defrauding JPMorgan

https://www.wsj.com/finance/startup-founder-charlie-javice-sentenced-to-more-than-7-years-for-def...
2•Geekette•26m ago•1 comments

We Gave Our AI $1k to Spend on Google Ads

https://julius.ai/articles/julius-ran-an-ad-campaign
12•zachperkel•27m ago•0 comments

Show HN: AI that trades speed for reliability in site generation

https://www.myzylo.app
1•rhettjull•28m ago•0 comments

Big Tech Told Kids to Code. The Jobs Didn’t Follow.

https://www.nytimes.com/2025/09/29/podcasts/the-daily/big-tech-told-kids-to-code-the-jobs-didnt-f...
8•voxadam•28m ago•2 comments

Your web images are probably oversized

https://reasonunderpressure.com/blog/posts/your-images-are-probably-oversized
3•mustaphah•29m ago•0 comments

Macintosh System 7 ported to x86 with LLM help

https://hackaday.com/2025/09/29/macintosh-system-7-ported-to-x86-with-llm-help/
1•manoDev•33m ago•1 comments

Ask HN: What are you working on? (September 2025)

24•david927•33m ago•45 comments

Deep dive into the new Cursor Hooks

https://blog.gitbutler.com/cursor-hooks-deep-dive
3•schacon•36m ago•0 comments