Mesh VPN 和私有网络
Tailscale 隐私评级
编辑推荐
基于 WireGuard 构建的网状 VPN,使用托管的协调服务器进行密钥交换和访问控制,将设备连接成私有网络,客户端为开源。
摘要
按Mesh VPN 和私有网络的标准,Tailscale 得分 50/100(等级 D)。 它满足 7 项标准中的 1 项:密钥保留在设备上。 它部分满足开源、无广告或数据出售、独立审计、自托管协调服务器和默认不记录连接日志。 它不满足无跟踪器或遥测。 它的总部位于加拿大:五眼联盟成员。
分数 50/100。 评分方式
标准
-
部分
开源 权重 3/3
运行产品所需的全部源代码是否都已公开?
The client daemon is BSD-3-Clause, but the Windows, macOS and iOS GUIs and the hosted coordination server are closed source.
-
否
无跟踪器或遥测 权重 3/3
网站和应用是否没有第三方跟踪器,任何统计分析均为匿名,且任何遥测默认关闭?
The website uses third-party analytics and advertising cookies, and client logging is on by default with an opt-out.
-
部分
无广告或数据出售 权重 2/3
产品的资金是否不依赖广告、广告定向或出售用户数据?
Funded by paid plans with no ads in the product, though the website shares cookie data with ad partners for Tailscale's own marketing.
-
部分
独立审计 权重 2/3
过去三年内是否发布过独立的安全或隐私审计?
Latacora conducts regular security audits, but the reports are only available on request.
-
是
密钥保留在设备上 权重 3/3
设备之间的流量是否使用在每台设备上生成的私钥加密,使协调服务器和中继无法读取?
Each device creates its own WireGuard key pair. The private key never leaves the device, and DERP relays only forward encrypted packets.
-
部分
自托管协调服务器 权重 2/3
协调服务器或控制服务器能否使用开源软件自托管?
Tailscale's coordination server is closed source. The clients can use the open-source, community-maintained Headscale server instead.
-
部分
默认不记录连接日志 权重 2/3
除非用户或管理员开启,连接日志和客户端诊断日志是否不会保存在供应商的服务器上?
Clients send logs to Tailscale by default, including connection open and close events. The --no-logs-no-support flag or TS_NO_LOGS_NO_SUPPORT turns this off.