‹ BackHN Continuity

Thread

Making Tailscale Faster

250 points · 112 comments · yarapavan

  1. iscoelho · · focus · HN ↗
    In my opinion, this is Tailscale's largest issue.

    It is slow. It cannot achieve speeds of greater than 1Gbps on clients systems (Windows & Mac), where you'd normally see it being used. On Linux, it struggles to achieve 10Gbps even when using a synthetic large packet benchmark [1]. With an IMIX benchmark, it would not be competitive whatsoever.

    This problem is fixable. WireGuard achieves higher performance (Kernel vs Userspace implementation) and IPsec implementations can achieve 100Gbps/400Gbps (DPDK/XDP). Zero-copy networking.

    From this blog post, I can say Tailscale still seems to not have the appetite for that, which is a shame.

    [1] <a href="https:&#x2F;&#x2F;tailscale.com&#x2F;blog&#x2F;more-throughput" rel="nofollow">https:&#x2F;&#x2F;tailscale.com&#x2F;blog&#x2F;more-throughput

    1. TZubiri · · focus · HN ↗
      &gt;(Kernel implementation)

      &gt;IPsec

      Remember that at least one LPE CVE associated to kernel IPSec implementation has been discovered (copy.fail), which means that whatever gains you get from this vpn tunneling, is lost by breaking the basic user security system guarantee.

      You are better off not using a VPN at all rather than using kernel crypto

      1. iscoelho · · focus · HN ↗
        By that logic, we should avoid TCP as the Linux kernel implementation has had plenty of CVEs. Thankfully our expert critical thinking helps us acknowledge that as silly.
        1. adgjlsfhk1 · · focus · HN ↗
          quic&#x2F;udp does seem to be the future
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.