{
  "id": 3565277,
  "title": "Tailcat",
  "url": "https://urgent.news/2026/08/26/tailcat",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-26T17:42:22.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://github.com/tailscale/tailcat"
  },
  "original_language": "en",
  "account": "Tailcat is a remix of Tailscale's open-source components to function like netcat, but over Tailscale's data plane without the control plane. Tailscale's data plane, known as magicsock, enables point-to-point WireGuard-encrypted tunnels between machines, using DERP for NAT-hole-punching communication and fallback relay if necessary. Connection metadata is exchanged out of band, via CLI or library. Tailcat runs a server (listener) and a client, exchanging a short connection token to establish communication, with end-to-end encryption via WireGuard. The connection initially traverses Tailscale's DERP relay network, then upgrades to direct peer-to-peer UDP when possible. No Tailscale account or root/admin access is required; it's a userspace library and CLI tool. Free rate-limited DERP relays are available, or users can run their own. Tailcat supports various server modes, such as SSH, enabling SSH servers reachable from anywhere by name without open inbound ports, leveraging WireGuard authentication. Users can also run their own DERP servers, run SSH servers with pinned servers by DERP region, or utilize their own DERP map for improved performance and privacy.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}