Sign in

James Tucker

@rag.pub
645 followers 155 following 300 posts

🧌 the original roflscaler I dodge hellthreads

PostsRepliesMedia
James Tucker @rag.pub · 22/09/2026
ECH is no silver bullet, DNS is too easy to manipulate in most real world cases with extra distortion/friction from captive portal inconsistencies and lack of standards uptake. but lets encrypt and friends offer IP certs, which is a reasonable step for now.
100
James Tucker @rag.pub · 22/09/2026
yeah, wireguard and disco are both quite easy to identify, as @apenwarr.ca mentioned already we don’t really want to become “evasive” - it’s a feature that organizations can protect themselves somewhat from us being used for exfil - but stuff that’s egregious blocking will slowly drive us that way
110
James Tucker @rag.pub · 22/09/2026
fwiw, we have nearly zero issues with blocking in china, we see far more arbitrary routing issues in the region. we _are regularly blocked_ by libraries and gymnasiums in the US due to arbitrary block lists folding us into "vpns" we're considering dropping named SNI for them.
120
James Tucker @rag.pub · 02/09/2026
fwiw, i sort of hate the ssh problem because it runs counter to what almost all simply written software needs/wants, so users end up asking for conflicting behaviors. i'm hoping once superlogical exists and then gets cloned well a few times we can generalize around that rather than ssh
000
James Tucker @rag.pub · 02/09/2026
the cases i plan to improve soonish (most of the code is in a branch somewhere, no timeline promises atm) are primarily where we have a well defined _local knowledge_ loss of access, when we know all routes locally have become unavailable and settled, key expired, peer expired, etc.
100
James Tucker @rag.pub · 01/09/2026
i do have some patches in flight to improve this, but other stuff keeps taking priority - we'll improve it eventually. it's still true we can't be perfect, but we can improve signalling carefully
000
Reposted by James Tucker
Ian McKellar @ian.mckellar.org · 30/08/2026
I vibe coded a map app that renames everything to "America" so that Trump can stop trying to rename stuff. americize.com
161
James Tucker @rag.pub · 27/08/2026
slop salad: an inorganic ecologically harmful word salad
000
James Tucker @rag.pub · 18/08/2026
Are you a zsh enjoyer?
110
James Tucker @rag.pub · 18/08/2026
re. subsystems, they're sort of on the way out in ssh - the preferred model is to just launch a program and use stdio (rsync, etc) systemd already implements exactly this! systemctl --host foo@foo.bar.ts.net list-units not only that, it also prints stderr correctly so check mode works great!
110
James Tucker @rag.pub · 05/08/2026
I’m more interested to find out what they did with the other protocols and identity systems
010
James Tucker @rag.pub · 15/07/2026
Out of interest what is your dac set to in midi settings (I know odd name but that’s where it lives in macOS - also it’s a standalone app not under system settings)
100
James Tucker @rag.pub · 14/07/2026
it's up to you philosophically if you want your "local first" traveling over a neutral open internet, or if you want all of your "local first" traffic immediately traversing a non-neutral private network from "edge to edge". there are technical merits to both, but the ecosystem concerns are bigger
040
James Tucker @rag.pub · 14/07/2026
Someone already mentioned that modern dacs are delta sigma and this difference doesn’t exist unless you have some very novel equipment. The 16->24 change shouldn’t have any impact on presentation, it should literally be a bit shift only, loss and error free. Something else is afoot.
020
James Tucker @rag.pub · 15/06/2026
Measles outbreak in SFO? What the fuck are we doing?
000
James Tucker @rag.pub · 10/06/2026
I posted on your ticket too, but FYI I've had success this afternoon/evening improving this, the next unstable builds should no longer have this disabled and the controlplane frontends are now also tentatively also supporting it. Thanks for the write-up and prompt.
010
James Tucker @rag.pub · 09/06/2026
ack, that's desirable for us too. at the moment the whole build chain follows from the same internal module, which is also where the godebug line was added to control this. that not being visible on the oss side was an oversight. to be clear the oss module isn't modified, it's imported there.
130
James Tucker @rag.pub · 09/06/2026
agreed
130
James Tucker @rag.pub · 09/06/2026
due to corporate middlebox deployments, we assume that the control tls connection may be mitm'd, which is the reason for the ts2021 protocol inside
120
James Tucker @rag.pub · 09/06/2026
we originally closed this to avoid an arbitrary step function of behavior and load controlled solely by a go version change in terms of the client <-> control connection, the clients prefer port 80, regardless of port the client switches to the ts2021 protocol inside (which will also evolve for pq)
210
James Tucker @rag.pub · 09/06/2026
very often yes, full dpi is expensive. wireguard is easy to identify by cheap properties in the handshake message, but harder afterward. disco is also very easy to identify though, so i wouldn't be surprised if it's eventually caught up in the mix
000
James Tucker @rag.pub · 04/06/2026
systemd-networkd remains unserious software, despite years of reports and pleas to the maintainers, they still react to a slow kernel interface by permanently de-configuring network interfaces taking nodes offline.
000
James Tucker @rag.pub · 02/06/2026
working outside in medium density rural America: the constant distant whinge of garden blowers
020
James Tucker @rag.pub · 29/05/2026
ah yeah, I have a thread of effort down this path to somewhat improve things, but nested pmtu in general is a complex topic so the road to perfection is long. hopefully it'll at least be much easier to debug soonish
110
James Tucker @rag.pub · 29/05/2026
i don't see any specific problem in your thread, but if you're running super recent distro kernels then this is likely it and we're landing workarounds rn: github.com/tailscale/ta...
100
James Tucker @rag.pub · 27/05/2026
if you want really good browser font rendering on linux, my firefox patch landed and so you can set: gfx.font_rendering.freetype.enhanced_contrast 100 gfx.font_rendering.freetype.gamma 0 for excellent subpixel AA no color fringing no ghostly stems the road to new defaults is unbounded, sadly.
030
James Tucker @rag.pub · 13/05/2026
google docs are a terrible way to discuss projects space constrained mid bandwidth high UX latency discussions on perceived post-facto work product is a massive hazard for authors and contributors alike i'm starting to think google docs might actually be a huge anti-culture for team cohesion
010
James Tucker @rag.pub · 02/05/2026
Oh and cve as a search keyword doesn’t help much anymore - for example Linux basically doesn’t bother anymore. You’ll see em for the branded stuff but there’s tons more going by every week which are just as strong for attackers
100
James Tucker @rag.pub · 02/05/2026
Trying to be ready to run untrusted programs in a multitenant deployment is full time attention to detail and a serious undertaking for bootstrapping. Like I said at the start - it’s such a mess the machine can’t do a good job feigning expertise. It got worse this month too.
100
James Tucker @rag.pub · 02/05/2026
Knowledgeable humans are much more effective at enumerating the obvious risks. I have evidence!
100
James Tucker @rag.pub · 01/05/2026
PSA I guess: the machine brain can't slop you together a real sandbox, it'll just tell you it can. the other machine brain will own you, and all of your users because the attackers know how to ask the right questions.
110
James Tucker @rag.pub · 01/05/2026
these days i translate "one shot" to "one slop" in my head when people tell me that's what they're doing
000
James Tucker @rag.pub · 27/04/2026
slophub
120
James Tucker @rag.pub · 26/04/2026
1Password has the start of the right general model. People still screw it up but the UI & UX do a lot to make it clear what to do with the secret (including making a physical copy) and they make digital copies lower friction. Signal is bad at this boundary, SS7 reliance and no backup is lossy
130
James Tucker @rag.pub · 25/04/2026
threatening people in response to feedback as to why your slop is insecure is not the right answer. people are so addicted to the reward loop they're forgetting to be decent
010
James Tucker @rag.pub · 24/04/2026
things I want from Go that I will probably never get: - goroutine park/wake without //linkname hacks - native fd & handle event watching (buffer free read/write/error waits, aka select(2)/poll/whatever) - i/o and events in select without channel forced allocation load
010
James Tucker @rag.pub · 22/04/2026
while people love to moan about systemd, i'm quietly here hoping one day they'll go after glibc at least at the nss boundary and replace that mess
000
James Tucker @rag.pub · 20/04/2026
Go's context constructor names are weird, it kinda gets me every time someone sets one up in main, neither of the constructor names make sense. New would have just made sense but there was fear of other people's behavior feeding into the design, the outcome is ironic and confusing to new users.
000
James Tucker @rag.pub · 13/04/2026
sadly it’s not very warming
000
James Tucker @rag.pub · 12/04/2026
now try it with latency
100
James Tucker @rag.pub · 08/04/2026
didn’t you hear though, they’re too busy being leet asm hackers, they don’t take reports from non-contributors
000
James Tucker @rag.pub · 08/04/2026
“Ghost murmur” or “Lucy in the sky with diamonds”
010
James Tucker @rag.pub · 07/04/2026
sure if you don’t use any of std most of std gets thrown out, but also 128kb for hello world is still extremely big
000
James Tucker @rag.pub · 06/04/2026
That’s useful for embedded. I just want to be able to write 20kb binaries for regular operating systems without doing backflips every damn time though, and then follow the gradient from there to embedded downward and from there to gui upward. stuff in std that adds megabytes I basically never use
110
James Tucker @rag.pub · 06/04/2026
you know what i want is a rust std replacement that is designed for systems programming. no mutexes around I/O, minimal allocs, defined but simple allocator, cheap fully swappable unwinder, etc. drop all the "conveniences" and just give me "raw" implementations for systems work.
100
James Tucker @rag.pub · 01/04/2026
I am so fed up of this systemd-networkd behavior, it's so braindead. I wish the lead would just fix it properly: Apr 01 00:04:43 hostname systemd-networkd[131147]: eth0: Could not set route: Connection timed out Apr 01 00:04:43 hostname systemd-networkd[131147]: eth0: Failed I see this a lot.
020
James Tucker @rag.pub · 26/03/2026
I’d be curious to see some code you can point at which shows the difference in a way that highlights how this distinction manifests in the non-abstract world. I’m not too sure the abstraction actually expresses once it hits implementation.
000
James Tucker @rag.pub · 26/03/2026
That’s not really true though, there is no network access if there is no service access. The presence of service access implicitly provisions network access as a convenience. In this regard it is service first.
110
James Tucker @rag.pub · 26/03/2026
Tailscale peers only see each other in the network map if they have an ACL allowing access in at least one direction to at least one service. If the number of services drop to zero they no longer see each other at all.
110
Reposted by James Tucker
Eric Lengyel @ericlengyel.bsky.social · 17/03/2026
New blog post: A Decade of Slug This talks about the evolution of the Slug font rendering algorithm, and it includes an exciting announcement: The patent has been dedicated to the public domain. terathon.com/blog/decade-...
1127386