Post B5r2QRxy9ElCxL6Tsu by star@amazonawaws.com
(DIR) More posts by star@amazonawaws.com
(DIR) Post #B5r2QRxy9ElCxL6Tsu by star@amazonawaws.com
0 likes, 0 repeats
I would love to know the opinions of network enthusiasts on NetBird, Pangolin and whether there are perhaps even better ways to do resource access management, zero trust and so on :neocat_think: :boost_requested:
(DIR) Post #B5r2V7jomdknfQiH5c by star@amazonawaws.com
0 likes, 0 repeats
cc @alina and @femsci :celeste_hearts_trans:
(DIR) Post #B5r6h87xYrHqANzAjg by alina@girldick.gay
2 likes, 0 repeats
@star @femsci speaking for my own infrastructure i generally dont want to rely on anything that considers itself a marketable product rather than a technology of the publici've heard about netbird before but never tried it, though from the fact that it calls itself a "wireguard-based overlay network" it is already hinting at the fact that it is indeed not zero trusthere they do a very poor job at explaining what zero trust is, and how it's supposed limitations affect their producthttps://netbird.io/knowledge-hub/open-source-zero-trust-networkingwhen accessing a web service for example, with an OIDC-enabled SSO that authenticates the browser session of the user, one can meaningfully restrict access to that browser. in their scenario of an employee running malware where they get pwned that is because they do the opposite of zero-trust and blindly route all network traffic to the intra-net, just because it runs on the same machinei think this is very misleadingalso lmao at these supposed network security experts telling you to install their product by running a curl pipe bash commandi think what you might like is the PAM-integration of kanidm, which also does SSO-bound ssh to remote machines. ssh3 as a protocol is also very much about OIDC-integration, so this is definitely not some killer feature of netbirdi cant speak precisely about their security model because they do not seem to provide a whitepaper and only marketing pages full of buzzwords meant for executives
(DIR) Post #B5rsJJIDC0gJe3ULqK by Lilith_demon_blood@tech.lgbt
1 likes, 0 repeats
@star From Kittens limited view they are a good way to secure selfhosted services behind a central Gateway, but Kittens experience stems from experimenting with stuff for maybe three quarters of a year.So far Kitten only had a reverse Proxy in front of her services, all services behind an SSO and tailscale for stuff, that should only be reachable by VPN.Pangolin and Netbird seem to combine reverse Proxy and VPN. From what Kitten gathered Netbird was similar to Tailscale before and only recently tried to be an all in one Gateway. Pangolin tried this approach from the very start and seems more focused on community than Netbird.There is an Enterprisr version of Pangolin, but you get a Key for free if your revenue is below a threshold or if you don't make any money with it.One thing to note though: Kitten didn't get around to trying netbird or Pangolin yet and only wants to use any of it for Services and not machines for ssh.
(DIR) Post #B5rsYy7TgK2wbwvzQ8 by star@amazonawaws.com
0 likes, 0 repeats
@alina @femsci thank you so much alinaaaa c: that's very helpful!!!! :neodog_hug_heart: :neodog_hug_heart: :neodog_hug_heart: :neodog_hug_heart: :neodog_hug_heart: :neodog_hug_heart: :neodog_hug_heart: :neodog_hug_heart: :neodog_hug_heart:
(DIR) Post #B5rsgWn9AbSIAi1sLQ by star@amazonawaws.com
0 likes, 0 repeats
@Lilith_demon_blood Thank you soooooooooo much lilith!!! :espeon_love: :espeon_love: :espeon_love: :espeon_love: :celeste_hearts_trans: very nice of you !!!
(DIR) Post #B5sjdqGNc8bFGOJ6Jc by Lilith_demon_blood@tech.lgbt
1 likes, 0 repeats
@star Always glad to help, especially when it's also one of kittens special interests :ablobcatheartsqueeze:Not only that but Kitten wants to set up something like this this year, when she has enough money for a vps, so the knowledge is pretty fresh.