frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A first look at Aperture by Tailscale (private alpha)

https://tailscale.com/blog/aperture-private-alpha
62•geoffeg•3h ago

Comments

frenchtoast8•1h ago
I'm not understanding how this supports Tailscale's initiatives and mission. That isn't to say this isn't a useful feature for a business, but it feels like a random grasp at "build something, anything, AI related." As a paying customer I'm concerned about the company's focus being blurred when there are 3.8k open issues on their Github repo and my company has been tracking some particular issues for years without progress.
esseph•1h ago
> my company has been tracking some particular issues for years without progress

Sounds like something your Account Manager or similar would need to work through. Development roadmaps are often driven by the largest, or loudest customers.

stopachka•1h ago
Another reason they could have built this was by listening to their users. I do believe lots of people are spinning up agents in their workplaces, and managing yet another set of api keys is probably annoying for Tailscale's customers. This feels like a great solution to me.
gneray•1h ago
This ^^

There's a set of common needs across these gateways, and everyone is building their own proxies and reinventing the wheel, which just feels unnecessary.

~All of our customers at Oso (the launch partner in the article) have been asking us how to get a handle on this stuff...bc their CEO/board/whatever is asking them. So to us it was a no-brainer. (We're also Tailscale customers.)

hwpky•1h ago
Pressure to service larger customers to capture higher revenues is inevitable for Tailscale given the scale of VC funding, valuation, and operating costs involved.

Trying to be all things to all people will inevitably dilute focus, and it’s understandable that OP might be looking at this sub-product and wondering where the value is for their use cases.

They’re probably not the only ones questioning whether they’re still part of Tailscale’s core ICP (ideal customer profile), either.

Edit: expanded ICP for clarity.

micromacrofoot•39m ago
yes this inevitably happens to companies that can't grow infinitely, you pivot to enterprise because you can sell to one person that has the equivalent spend of thousands... it really is unfortunate for the individuals
verdverm•1h ago
I have a secret manager, why would I want tails ale involved in the management of secrets, they are a networking company

Tails ale is not a company I see being involved in my core AI ops. I don't need their visibility tools, I already have LGTM.

Tailscale should focus on their core competency, not chase the gilded Ai hype cycle. I have sufficient complaints about their core product that this effort is a red flag for me. To do this now, instead of years ago, shows how behind the times they are

wildzzz•1h ago
A huge chunk of the open issues are feature requests with many of those already being implemented years ago but not yet marked closed. And a vast majority of the bugs are repeats, they clearly need someone to clean up their issue tracker.
preisschild•1h ago
+1

I like tailscale itself but a lot of basic stuff (such as dynamic routing) or ephemeral node auth are very lacking, wish they would concentrate more on their core product we all like and want to see improve

9rx•1h ago
> we all like

Building software users like doesn't make for a good business model. Especially if that model has to satisfy VC.

dbushell•1h ago
I realised I wasn't Tailscale's target customer when I reported a 100% reproducible iOS bug/regression over a year ago. It was confirmed, logged, and forgotten.
tptacek•1h ago
Corporate/enterprise networks have nightmarish setups for centralizing access to LLMs. This seems like an extremely natural direction for Tailscale; it is to LLM interfaces what Tailscale itself was to VPNs, a drastically simplified system that, by making policy legible, actually allows security teams to do the access control that was mostly aspirational under the status quo ante.

Seems straightforward?

I think if you don't have friends working at e.g. big banks or whatever, you might not grok just how nutty it is to try to run simple agent workflows.

Bluecobra•54m ago
>Corporate/enterprise networks have nightmarish setups for centralizing access to LLMs.

As someone who is on the other side of the fence on this and trying to keep the network secure and preventing data exfiltration there could be a good reason for this. More often than not we have folks doing all kinds of crazy things and ignore what’s in the handbook. For example we had someone who didn’t like MFA for remote access and would use Tailscale to have a remote permanent reverse proxy to their homelab to do whatever work they were doing. What’s funny is that we are not BOFH’s and would have helped them setup whatever they need had they just sent us an email or opened a ticket.

tptacek•48m ago
The whole Tailscale ethos is exactly what you're talking about:

* Security/risk teams have coherent, sensible goals for managing access

* The technology stack they've landed on makes those goals performative; so complicated that they can't even express their most important goals, so annoying that users route around it

* What's needed is a radically simplified approach that centers end-user experience (particularly around onboarding).

I'm not saying banks are crazy to want to control LLM usage (I'm not bullish on it long-term either, but I see the issue), just that the systems I've talked to friends about them using today are batshit, ranging from "foundation lab shmoundation lab we'll just do our own models" to "OK you can operate in 2025 but only in a Citrix terminal".

notepad0x90•1h ago
In times of peace, the hardest part of running a military is keeping the troops busy.
_pdp_•59m ago
Came to say this. It looks like a Mozilla move.
sauercrowd•29m ago
This seems quite useful to me, especially for a larger org. If your dev's are working on LLM features, they'll need access to the OpenAI APIs. So are you just gonna give all of them a key? the same key?

No idea how this is solved at the moment, so seems like a smart step

scottyah•7m ago
There's actually a mass acquisition game going on right now in this space. Companies want to use genAI, but don't necessarily want to hire people to run their own models in-house. It may not be obvious to startup-y employees, but keeping data in-house is huge for big companies. LLM traffic is a lot different from established traffic that firewalls have been built up for. You can't block data leaks as easily as shutting down access to google drive. When you can't trust all of your employees, genAI presents a lot of new attack vectors.
SSLy•46m ago
unrelated, but what's the path of least resistance to expose a couple of localhost-bound services to the tailnet, ideally with each having own hostname entry as the browser sees it?

they're not containerised, just plain old daemons.

lkosewsk•40m ago
Give Tailscale serve a shot (https://tailscale.com/kb/1312/serve).

*edited; I initially pointed to Funnel which would be used for sharing outside your tailnet.

timwis•38m ago
This should work out of the box with Magic DNS (part of tailscale features). If machine A is named larrys-laptop and is running a service on :8080, then from sandras-laptop just navigate to http://larrys-laptop:8080 and it should work, provided both machines are on the same tailnet.
JayWS•27m ago
https://tailscale.com/kb/1552/tailscale-services

Tailscale services will do that. You can do the proxying with tailscale serve, services gives you the MagicDNS name and virtual IP address bound to it.

cratermoon•23m ago
Hop on the hype train before it crashes!
sheepscreek•16m ago
Not trying to diss or anything but a capable engineer could spin this up within their organization in a day or two. So I’m not sure how useful this is going to be to the average customer. Perhaps to the largest customers who have sophisticated security and compliance needs but even for them this would need to be very very competitively priced to be worthwhile (cheaper than the salary of 2 devs for a year).

The true moat of Tailscale is the core product. That can’t be easily replicated (still). Perhaps some product to simplify controlling what resources agents in the organization have access to and having 100% visibility + audatability for them will be way more useful.

storystarling•3m ago
I built a similar gateway for my own stack and thought it would be a quick project, but the complexity is hidden in the details. A basic proxy is simple enough, but getting accurate token counts for streaming responses turned out to be a huge pain since every provider handles chunks differently. You also end up spending a lot of time writing adapters to unify the schemas so your application logic stays clean. If you care about precise billing or logging, it is definitely not a two day build.

430k-year-old well-preserved wooden tools are the oldest ever found

https://www.nytimes.com/2026/01/26/science/archaeology-neanderthals-tools.html
215•bookofjoe•4h ago•126 comments

Prism

https://openai.com/index/introducing-prism
74•meetpateltech•2h ago•26 comments

SoundCloud Data Breach Now on HaveIBeenPwned

https://haveibeenpwned.com/Breach/SoundCloud
85•gnabgib•2h ago•30 comments

Lennart Poettering, Christian Brauner founded a new company

https://amutable.com/about
79•hornedhob•1h ago•66 comments

Clawdbot Renames to Moltbot

https://github.com/moltbot/moltbot/commit/6d16a658e5ebe6ce15856565a47090d5b9d5dfb6
29•philip1209•1h ago•4 comments

OpenSSL: Stack buffer overflow in CMS AuthEnvelopedData parsing

https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467
55•MagerValp•3h ago•29 comments

Flexible use of a multi-purpose tool by a cow

https://doi.org/10.1016/j.cub.2025.11.059
48•PlaceboGazebo•5d ago•8 comments

I made my own Git

https://tonystr.net/blog/git_immitation
288•TonyStr•9h ago•124 comments

Hypercubic (YC F25) Is Hiring a Founding SWE and COBOL Engineer

https://www.ycombinator.com/companies/hypercubic/jobs
1•sai18•1h ago

FBI is investigating Minnesota Signal chats tracking ICE

https://www.nbcnews.com/tech/internet/fbi-investigating-minnesota-signal-minneapolis-group-ice-pa...
79•duxup•2h ago•64 comments

Bassoontracker, Tracking in the Browser

https://www.stef.be/bassoontracker/
18•jdboyd•11h ago•3 comments

Arm's Cortex A725 Ft. Dell's Pro Max with GB10

https://chipsandcheese.com/p/arms-cortex-a725-ft-dells-pro-max
11•pixelpoet•1h ago•0 comments

Chuck Klosterman on why we've never actually seen a real football game

https://www.latimes.com/entertainment-arts/books/story/2026-01-22/chuck-klosterman-new-book-football
3•proposal•8m ago•1 comments

Heathrow scraps liquid container limit

https://www.bbc.com/news/articles/c1evvx89559o
578•robotsliketea•4d ago•745 comments

AI2: Open Coding Agents

https://allenai.org/blog/open-coding-agents
28•publicmatt•2h ago•6 comments

Show HN: LemonSlice – Upgrade your voice agents to real-time video

26•lcolucci•2h ago•46 comments

Cloudflare claimed they implemented Matrix on Cloudflare workers. They didn't

https://tech.lgbt/@JadedBlueEyes/115967791152135761
399•JadedBlueEyes•4h ago•153 comments

Xfwl4 – The Roadmap for a Xfce Wayland Compositor

https://alexxcons.github.io/blogpost_15.html
212•pantalaimon•6h ago•162 comments

Doing the thing is doing the thing

https://www.softwaredesign.ing/blog/doing-the-thing-is-doing-the-thing
56•prakhar897•13h ago•11 comments

A first look at Aperture by Tailscale (private alpha)

https://tailscale.com/blog/aperture-private-alpha
63•geoffeg•3h ago•26 comments

One Human and One Agent = One Browser from Scratch

https://simonwillison.net/2026/Jan/27/one-human-one-agent-one-browser/
26•pretext•2h ago•10 comments

U.S. government has lost more than 10k STEM PhDs since Trump took office

https://www.science.org/content/article/u-s-government-has-lost-more-10-000-stem-ph-d-s-trump-too...
297•j_maffe•1h ago•187 comments

The threat eating away at museum treasures

https://www.scientificamerican.com/article/how-extremophile-molds-are-destroying-museum-artifacts/
7•sohkamyung•4d ago•2 comments

Two Twisty Shapes Resolve a Centuries-Old Topology Puzzle

https://www.quantamagazine.org/two-twisty-shapes-resolve-a-centuries-old-topology-puzzle-20260120/
40•tzury•23h ago•2 comments

A simulation where life unfolds in real time

https://soupof.life
78•maybe-tomorrow•6d ago•41 comments

Snow Simulation Toy

https://potch.me/2026/snow-simulation-toy.html
151•surprisetalk•1w ago•39 comments

TikTok users can't upload anti-ICE videos. The company blames tech issues

https://www.cnn.com/2026/01/26/tech/tiktok-ice-censorship-glitch-cec
995•kotaKat•6h ago•691 comments

Velox: A Port of Tauri to Swift by Miguel de Icaza

https://github.com/velox-apps/velox
162•wahnfrieden•1w ago•68 comments

A list of fun destinations for telnet

https://telnet.org/htm/places.htm
267•tokyobreakfast•16h ago•90 comments

The age of Pump and Dump software

https://tautvilas.medium.com/software-pump-and-dump-c8a9a73d313b
176•brisky•6h ago•63 comments