[HN Gopher] Apple TV, now with more Tailscale
       ___________________________________________________________________
        
       Apple TV, now with more Tailscale
        
       Author : mfiguiere
       Score  : 276 points
       Date   : 2023-09-18 19:24 UTC (3 hours ago)
        
 (HTM) web link (tailscale.com)
 (TXT) w3m dump (tailscale.com)
        
       | FireBeyond wrote:
       | I don't care either way, but I did note the ignorance of the
       | elephant in the room as to why 99% of people would care about
       | Tailscale and native VPN support on their Apple TV... and it's
       | not "avoiding sketchy wifi networks".
        
         | fotta wrote:
         | > With a Tailscale exit node, you're in control and you get the
         | internet connection you're used to. This new feature could come
         | in handy if you're traveling with your Apple TV and want to
         | access the same geo-restricted channels you can see from home.
         | 
         | They do call this out towards the end.
        
           | cassianoleal wrote:
           | How's this supposed to work? If I'm travelling with my Apple
           | TV and use it as an exit node, it's as geo-restricted as I
           | am, wherever I am.
        
             | ezfe wrote:
             | This blog post isn't just for using it as an exit node.
             | Traveling with the Apple TV and using Tailscale lets you
             | exit-node back to your house.
             | 
             | Traveling without the Apple TV and the exit-node can be
             | your Apple TV.
        
             | Larrikin wrote:
             | You designated a device at home as the exit node and are
             | using that on your Apple TV in a different location.
        
         | copperx wrote:
         | For sharing Netflix accounts?
        
           | fragmede wrote:
           | Arrr, it not be for Netflix.
        
             | tredre3 wrote:
             | Tailscale isn't useful for piracy. Unless you really want
             | your pirate traffic to always be routed through your home?
        
               | ezfe wrote:
               | Tailscale has Mullvad integration now, so it can be used
               | that way too
        
               | tshaddox wrote:
               | The idea is that you host all your pirated media from
               | home, e.g. on a NAS running Plex or Jellyfin, and your
               | home server can stream any of your media to any device
               | (including transcoding it to best fit the device and
               | connection).
               | 
               | Tailscale isn't particularly useful for acquiring the
               | pirated media in the first place, of course.
        
               | cellu wrote:
               | I guess it's more to be able to access the local are
               | stack / jellyfin from everywhere?
        
         | unstatusthequo wrote:
         | Because say I want to connect to my own private remote network.
         | I have a server hosted in a datacenter because I self-host. I'd
         | much rather have VPN capabilities than deal with a proxy server
         | and publicly open ports with rules. This is a much tighter way
         | to do things, IMHO.
        
         | LoganDark wrote:
         | It's a way to access it remotely without having to forward a
         | port to the whole world. There are other ways to do this, but a
         | VPN is usually the most straightforward option.
         | 
         | It's also a way to proxy your connections through a device at
         | home, of course. Whether the Apple TV is the client or the exit
         | node.
        
         | meowtimemania wrote:
         | The main use case I see is sharing streaming services like
         | youtube TV with family.
        
           | radicaldreamer wrote:
           | You can already do that officially... but maybe not region-
           | locked sports
        
             | sangnoir wrote:
             | It's cheaper if everyone is in the "same household" (i.e.
             | sharing the same public IP as main account)
        
             | drewnick wrote:
             | Definitely not region locked sports. My YT TV account is
             | based on the other side of the country and I can't watch
             | our local teams quite frequently. I've been using wireguard
             | and a dedicated wifi network to tunnel through a fiber
             | connection "back home" and it then thinks I am local and
             | all works well. This is much cleaner with tailscale!
        
           | zikduruqe wrote:
           | I run my own DNS server at home, and have Tailscale installed
           | on it also. I use this so when I am away from home, I can
           | continue to use it via Tailscale and/or an exit node for full
           | on VPN-like solution.
           | 
           | I can now, move Tailscale off that server, and put it on my
           | Apple TV to use as my network for my DNS server when I am
           | away from the house.
        
       | unstatusthequo wrote:
       | This is great news! Not only does this make a remote Plex /
       | Jellyfin media server easier to deal with, the Apple TV can be an
       | exit node. Solid work, TailScale!
        
         | maxmcd wrote:
         | I'm a little unfamiliar with how Plex routing works. Would this
         | make it so that your plex connected media servers don't need to
         | be publicly routabel and the Plex app will know to connect
         | through the tailscale network?
         | 
         | Would you need to reconfigure plex to use the tailscale ip
         | addresses and then the Apple TX Plex app will stream over that
         | address?
        
           | aaomidi wrote:
           | Depends on how you've setup Plex, but you can give it custom
           | access URLs. So you can expose both a public and a private
           | endpoint. Or just a private endpoint, up to you really.
        
           | ecliptik wrote:
           | I wrote up a guide [1] on using Plex + Tailscale + HTTPS last
           | year to setup Plex so you don't have to expose it through the
           | Plex relays or setup port forwards for other devices on a
           | Tailnet.
           | 
           | I would assume with this announcement, you can keep Plex
           | private to your Tailnet and an AppleTV also on the Tailnet
           | could use it without any port fowarding.
           | 
           | 1. https://forums.plex.tv/t/remote-access-using-tailscale-
           | magic...
        
             | SV_BubbleTime wrote:
             | >setup port forwards for other devices on a Tailnet.
             | 
             | Ah. Now I get it.
        
       | Operyl wrote:
       | Using it as an always-on exit node is actually a pretty nifty
       | feature, I hadn't thought about that as a viable feature before
       | now.
        
         | cube2222 wrote:
         | This is by the way kind of how remote access with apple home
         | works.
         | 
         | The Apple TV serves as a local gateway relaying all the
         | commands to your local IoT devices.
         | 
         | On a side note, tailscale is lovely. I have nothing but good
         | things to say about them.
        
           | Operyl wrote:
           | Yup, either a HomePod, Apple TV, or iPad left at home can act
           | as a HomeKit hub.
        
             | ericswpark wrote:
             | Just an FYI, but iPads can no longer be used as a HomeKit
             | hub as of last year: https://support.apple.com/en-
             | us/HT213481
             | 
             | (Yes, you can _technically_ use an iPad as a hub if you are
             | on the old Home architecture)
        
               | Operyl wrote:
               | Good change, then! It wasn't a great experience for most
               | people. iPads are rarely static home fixtures now, and
               | they were the only ones capable of dying.
        
       | judge2020 wrote:
       | > Finally, the new Tailscale client allows an Apple TV to be an
       | exit node itself for other machines in your tailnet.
       | 
       | Pretty huge. Many non-techy users don't like the idea of keeping
       | a computer on 24/7, but a smart TV is just fine.
       | 
       | Also, the Apple TV 4k only draws 0.5 watts at idle and less than
       | 3 watts when streaming movies[0], so I imagine it pulls less than
       | 1 just tunnelling traffic. Computers pull 15W+ at idle, and
       | that's with low end components.
       | 
       | 0:
       | https://www.apple.com/environment/pdf/products/appletv/Apple...
        
         | jondwillis wrote:
         | Neat, maybe I can sell my M1 mini server
        
         | MuffinFlavored wrote:
         | > Many non-techy users
         | 
         | Why would a non-techy user want to volunteer to be an exit
         | node?
        
           | notatoad wrote:
           | tailnets are private. you're not "volunteering" to be an exit
           | node for other people like a tor exit node, you're just
           | routing your own traffic through your home internet
           | connection.
           | 
           | if you travel and you want your traffic to always appear like
           | it's coming from your home network, being able to send it
           | through your appletv is cool.
        
           | fragmede wrote:
           | [delayed]
        
         | aaomidi wrote:
         | I had not convinced the use case of using this as an exit node.
         | Fuck this simplified so much.
        
           | copperx wrote:
           | Tailscale also runs on Android TV. If you don't have an Apple
           | TV and want a cheap device just to have an exit node, you can
           | buy a $20 Android TV thingy.
        
             | mjs wrote:
             | It ... kind of does, but if you filter the reviews by "TV"
             | you'll see there's quite a few issues with it: https://play
             | .google.com/store/apps/details?id=com.tailscale..... Not
             | sure why the back button issue hasn't been fixed, that
             | makes it very inconvenient to set up. (Also: are you sure
             | it can be used as an exit node? That wasn't supported a few
             | months ago.)
        
             | vosper wrote:
             | Beware that a lot of cheap Android TV boxes come pre-loaded
             | with heaps of malware. You don't want them in your network.
             | 
             | Linus Tech Tips has a video about it:
             | https://www.youtube.com/watch?v=1vpepaQ-VQQ&themeRefresh=1
        
         | lnxg33k1 wrote:
         | So far I've used it to get vpn on apple tv and i dont think i
         | am going to change, also considering how apple leaks vpns like
         | there's no tomorrow https://www.amazon.nl/GL-iNet-GL-
         | MT300N-V2-Reiserouter-Repea...
        
           | close04 wrote:
           | Can second the recommendation for the Mango travel router. I
           | always prefer to take the VPN out of the "hands" of the
           | client device to avoid any leaks. With 2 such devices
           | connected via Wireguard VPN any other device I connect to
           | that client router's WiFi is safely communicating through
           | that VPN. A sort of site to site VPN that works for devices
           | that could never otherwise use a VPN client.
           | 
           | But of course this is a different use case and not always an
           | option. Not if you want to use Tailscale. Probably unless
           | that Apple TV is already connected to one of this "VPN WiFi"
           | with Tailscale on top (no idea what the functionality or
           | performance impact is).
        
       | Spooky23 wrote:
       | Can you use this to appear to be in another place for blackout
       | avoidance purposes?
        
       | sohrob wrote:
       | Awesome news and boosts the utility of the Apple TV tremendously.
        
       | Timber-6539 wrote:
       | I wish they would work on their Android client.
       | 
       | Its got a long standing request to add split tunnelling [0] (a
       | standard feature on pretty much every VPN client you'll come
       | across). But it seems in the spirit of re-inventing existing
       | networking technologies, Tailscale also decided to re-invent what
       | a VPN client does.
       | 
       | This alone makes me give this otherwise wonderful project a pass
       | despite all the deservingly good press it gets.
       | 
       | [0] https://github.com/tailscale/tailscale/issues/6912
        
       | dimgl wrote:
       | Tailscale continues to be one of the more impressive services
       | I've ever used. Going to install this on my Apple TV immediately.
       | I often travel and use public Wi-Fi, so this is massively useful
       | as my PC and my laptop are not always on (so I can't use them as
       | an exit node). Pretty genius honestly.
        
       | syntaxing wrote:
       | Is it possible to run a plex or jellyfin server on an Apple TV
       | like a Nvidia Shield? If so, I might seriously consider getting
       | an Apple TV just to run as a media server.
        
         | billyhoffman wrote:
         | Sadly an Apple TV can't also be the media server (at least for
         | something like Plex). But just about anything else can run
         | media server, and you can go really low end especially if you
         | don't need it to transcode your media. Some software like
         | Infuse will stream the original media file to the Apple TV, and
         | the transcoding happens on device.
        
           | syntaxing wrote:
           | I more or less have running every through a N100 and it has
           | been great. Would have been awesome to replace it with an
           | Apple TV though
        
           | tshaddox wrote:
           | True, but of course if you already have a media server, it
           | can almost certainly already act as a Tailscale exit node.
        
       | zakki wrote:
       | I wish there is Tailscale for LG TV.
        
         | ilteris wrote:
         | Never heard of tailscale before. Is it similar to Plex?
        
       | nickvanw wrote:
       | This is useful - using an exit node with an Apple TV is useful as
       | well for navigating around certain tools that are geo-blocked.
       | Before, you'd have to handle it outside of the device which is
       | much more difficult.
       | 
       | I'm going to play around with this later in the week.
        
       | klinquist wrote:
       | This makes it much easier to use the Xfinity Stream app on your
       | "travel appletv" :)
        
       | ShakataGaNai wrote:
       | This is very cool, and very useful.
       | 
       | For the average, non-technical user, Apple TV as an exit node for
       | other device while traveling is super cool.
       | 
       | But for someone who is out of the country for a duration, it's
       | also super handy. Netflix knows all the popular VPN providers and
       | ban hammers them on a regular basis. But being able to use _my_
       | Apple TV to watch my normal Netflix (or whomever) from any other
       | country... because they think I 'm at home? Super win.
        
         | fragmede wrote:
         | Network engineers watching rtt/packet latency very closely can
         | still tell that something fishy is up, but Netflix doesn't
         | really want to block VPNs, they just have to pretend to care
         | enough so that the labels don't pull their content.
        
       | aaomidi wrote:
       | I've been working on bringing tailscale into container networking
       | through a driver, it's still a work in progress but people might
       | already be interested in trying it out:
       | 
       | https://github.com/aaomidi/ContainerScale
        
       | drexlspivey wrote:
       | The bigger news is that you can add VPNs on Apple TV with tvOS
       | 17, I had to run it on my router before
        
       | b555 wrote:
       | can anyone share documentation/paper/video with eli5 of
       | tailscale?
       | 
       | i recently read this with mulvad too and feel stupid that I don't
       | intuitively understand how it works, and what it does and why
       | it's needed.
        
         | duped wrote:
         | You're on a team of 10 people with 20 different machines
         | between you and want to securely send/receive files, spin up
         | servers and talk to them, etc.
         | 
         | Tailscale makes this really easy, and fast.
        
         | angott wrote:
         | This blog post is a very good technical read (and the diagrams
         | are really cool too): https://tailscale.com/blog/how-tailscale-
         | works/
        
         | SparkyMcUnicorn wrote:
         | Tailscale is basically wireguard in a seamless UX wrapper, and
         | a bunch of nice (optional) things added on top like
         | ACLs/2FA/MagicDNS/ssh.
         | 
         | https://tailscale.com/blog/how-tailscale-works/
        
         | simonw wrote:
         | It's WireGuard with a really nice UI.
         | 
         | WireGuard is an outstanding mechanism for building secure
         | virtual private networks.
         | 
         | You can run WireGuard on a bunch of different machines (or
         | virtual machines) spread all over the world and give them the
         | ability to talk to each other as if they were on the same LAN,
         | with every packet fully encrypted.
         | 
         | TailScale has productized this. They wrote software for a bunch
         | of platforms that makes it trivial to connect those machines to
         | your "tailnet" - effectively a WireGuard network which their
         | software manages for you.
         | 
         | They tie this to SSO - so you can install their software on
         | your phone and your home server, sign them both in using Google
         | SSO or similar, and now they're able to talk to each other on a
         | secure virtual network.
         | 
         | I suggest trying the TailScale setup process to really
         | understand how good it is.
        
           | hot_gril wrote:
           | So it's a VPN, right?
        
             | ezfe wrote:
             | It's kinda a VPN.
             | 
             | Tailscale on its own is a mesh network that allows your
             | devices to communicate (in a VPN, technically, yes) between
             | themselves.
             | 
             | If you have an exit node, then you can route your traffic
             | to that exit node in the way most people think of a VPN.
             | 
             | It also has Mullvad integration, providing Mullvad servers
             | as exit nodes.
             | 
             | If you use an exit node, then its functionally equivalent
             | to a VPN with fancy features.
        
         | ecliptik wrote:
         | It's a 90s LAN, but with encryption and accessible from
         | anywhere.
        
         | Larrikin wrote:
         | You have a home server, could be home assistant, a Raspberry
         | Pi, your desktop computer. Access that server and all services
         | on your phone or laptop from anywhere without figuring out
         | ports and worrying about your server being pwned. It all looks
         | like local traffic.
         | 
         | Set the DNS server on your phone to a Pi running AdGuard Home
         | and block all ads and trackers when on 5G, not just in the
         | browser.
         | 
         | Travel abroad with your laptop and designate your computer at
         | home as an exit node and now all the traffic on your laptop
         | looks like it is coming from that country.
         | 
         | Those are just the use cases I am using personally.
        
       | Mandatum wrote:
       | I live reading copy that's obviously written by nerds. This is
       | the least corporate announcement I've seen from a corporation in
       | a long time.
       | 
       | No mention of how much they live trust and privacy or how they're
       | going to make your experience more delightful.
        
         | ant6n wrote:
         | Yeah, sounds like a bunch of tech gobbledigook. I guess it's
         | written for the users of these services, and they know what all
         | this jargon means.
        
       | miki123211 wrote:
       | > With up to three users available on our Free plan, you've got
       | tools to make a media drive available to other trusted people in
       | your life. You can share a collection of family photos and home
       | videos into a faraway relative's tailnet, without worrying about
       | locking down the server for public internet access.
       | 
       | It's important to point out here that, in addition to this, the
       | free plan also lets you send invite links to specific devices,
       | which other people can add on their own accounts. That way,
       | nobody has to go for the (quite expensive and obviously company-
       | focused) free plan, you can share your device with as many
       | friends as you like, and you're not sharing anything else beyond
       | that single device.
        
       | mlfreeman wrote:
       | Will this work with Headscale too?
        
         | angott wrote:
         | Tailscale dev here: yes, you can set up a custom coordination
         | server in the settings, just like on the iOS app. Open the tvOS
         | Settings app, then scroll down to Tailscale.
        
           | hzia wrote:
           | Thank you so much for that!! I wondered about this as well.
           | Love how above and beyond you guys are going to support other
           | OSS implementations <3
        
       | jedberg wrote:
       | > But even if you don't have a media server to connect to, you
       | can use Tailscale's Apple TV app to select another device in your
       | tailnet ... to use as an exit node. This will route all your
       | Apple TV's traffic through that connection ... making your
       | traffic appear to originate from the machine of your choice.
       | 
       | Oh look all of those family Netflix devices are in one home
       | again!
        
         | [deleted]
        
       ___________________________________________________________________
       (page generated 2023-09-18 23:00 UTC)