> Layer 2 VPN is where it’s at anyway. I want to be on my LAN not managing one device or app at a time, I never got the wireguard hype.
You can do that though? Tailscale can as well. A device can advertise subnets, and can route them through tailscale, so you just need a single node in a LAN.
> A device can advertise subnets, and can route them through tailscale
This is still L3 layer though. One the main use case of L2 is proper DHCP propagation and avoid subnet collisions.
I do not think that this matters in practices though. Only a limited amount of user facing service require proper L2 emulation (apple TVs ?)
Or anything that uses multicast. The idea is you want homoiconic networking behavior and portability between local and remote. Hacking in special routing and subnets in L3 doesn’t give you that.
I find Passkeys are amazing once you accept they are not your only path in, just a much more convenient one. Have your accounts and totp with an authenticator set up, but add on every device you like a passkey to create a fast path.
Removes the need for syncing any passkeys, the risk of getting locked out, and the terrible support of 3rd party password managers providing passkeys
I'm pretty impressed how openai is both extremly verticalized but also building products across the whole depth of that stack.
Not sure if they're just trying to find what the abstractions are worth focusing, or if it will stay that way, but certainly cool to see how much they're trying out.
It certainly feels like they are throwing stuff at the wall to see what sticks.
Makes sense to me. The cost of shipping products is lower than ever and they have lots of talented folks who want to ship things. No one knows what could be the next killer app.
They have everyone's attention. They have access to newest AI stuff. They can say, "we need ideas to make money, don't make mistakes, generate the code, make a marketing post".
> If you do need a short-lived, signed token for something, there is a better spec called PASETO which is designed to be secure
Suggesting to non security people (like myself) something for auth that isn't a mainstream idea seems like a bad idea? Not to mention that it doesn't refer any reasons why it's better
I always snarked at clueless CEOs bent on forcing me to sign NDAs while the entire infra _and_ data was living in US from the get go. Like, what's so sensitive I'm going to disclose that wasn't voluntarily disclosed by yourself already?
Had a pixelbook and it was hands down one of the best laptops I ever had. Sure, ChromeOS is fairly boxed in but the Linux VM was reasonably good and the built quality was just something else.
I wish they'd just make ~ pixelbook with ubuntu... it'd be such a powermove, and they if anyone could pull it off
I was excited at first by this, but the "designed for gemini intelligence"... like what does that even mean
You can do that though? Tailscale can as well. A device can advertise subnets, and can route them through tailscale, so you just need a single node in a LAN.
reply