# Duckdns vs tailscale : security

**URL:** <https://help.nextcloud.com/t/duckdns-vs-tailscale-security/179691>\
**Category:** ℹ️ Support\
**Tags:** mfa, security, dns\
**Created:** [January 22, 2024, 7:27pm UTC](https://help.nextcloud.com/t/duckdns-vs-tailscale-security/179691 "2024-01-22T19:27:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Minty95](https://help.nextcloud.com/letter_avatar/minty95/32/5_5575768a8748004e209b776fc1b2916d.png) [@Minty95](https://help.nextcloud.com/u/Minty95)\
**Post date:** [January 22, 2024, 7:27pm UTC](https://help.nextcloud.com/t/duckdns-vs-tailscale-security/179691/1 "2024-01-22T19:27:04Z")

</div>

Hello

I have a self hosted Nextcloud installed on one of my computers. All is okay

Until today I normally use [duckdns.org](http://duckdns.org)  
"https:1244duckdns.org.mynextcloud…” to access it

But after playing around with tailscale I can now use “https:1234tailscale.mynextcloud…”

I have the ssl certificates for both, so both are using https. And 2FA for my login

Am I right in thinking that using #tailscale is slightly safer than #duckdns. Because with tailscale I don’t need to open the 443 port. Or is there no difference

The only difference that I can see is the port being configured open on my router for duckdns to run. Which I don’t need for tailscale

I can access both via my browser or my telephone. Both work perfectly.

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [January 24, 2024, 8:17pm UTC](https://help.nextcloud.com/t/duckdns-vs-tailscale-security/179691/2 "2024-01-24T20:17:25Z")

</div>

I don’t think is a a difference in terms of security. One method might look little safer at first glance as it doesn’t require port forwarding but if you create a public certificate your domain becomes public due to certificate transparency and everybody knows there is a service hosted on this address… more or less no difference the attacker scans your IP and discovers the service - depending on POV first method might seem even easier - you get the DNS name for free…

security doesn’t benefit from hidden knowledge - “security by obscurity” doesn’t work - it benefits from up-to-date software, good passwords and _Multi Factor Authentication_

#mfa #security

- [Nextcloud behind router with port forwarding disabled - security concerns and improvements using Tailscale?](https://help.nextcloud.com/t/nextcloud-behind-router-with-port-forwarding-disabled-security-concerns-and-improvements-using-tailscale/162768)

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [January 16, 2025, 8:53am UTC](https://help.nextcloud.com/t/duckdns-vs-tailscale-security/179691/3 "2025-01-16T08:53:55Z")

</div>


