Tailscale on Jailbroken Kindle Gets Proxy and TUN Modes
From E-Reader to Tailnet Node: A Major Upgrade
The journey of turning a jailbroken Amazon Kindle into a functional Tailscale node has taken a significant leap forward. An updated community client, building on Mitanshu Sukhwani's original work, now brings proxy and TUN modes to these low-power e-readers, unlocking capabilities far beyond basic connectivity.
This isn't just an incremental patch; it's a re-architecture of how Tailscale interacts with the Kindle's constrained operating system. The key improvements, spearheaded by developer greywolf1499 on GitHub, address the fundamental limitation that previously hampered the Kindle's utility as a networked device.
Overcoming the Userspace Barrier
Earlier iterations of Tailscale on the Kindle forced the client into userspace mode. This meant the device could announce its presence on a tailnet, but it couldn't route traffic from its own apps to other tailnet nodes. If you launched KOReader and tried to reach a Calibre server at a Tailscale IP, the connection would fail because the Kindle's root OS lacked the necessary routing rules.
The new implementation changes this by offering two distinct operational modes. The first is a proxy mode, which sets up a local SOCKS5 or HTTP CONNECT proxy on 127.0.0.1:1055. Apps like KOReader can be configured to use this proxy, effectively routing their traffic through Tailscale's daemon, tailscaled.
The second, more ambitious mode is a full TUN mode. On supported Kindle models, this enables kernel-level networking, allowing Tailscale to operate at the device level rather than just the application level. This is a complex feat on such a resource-constrained device, but it promises a more seamless integration where all network traffic is handled by Tailscale.
Practical Applications: From Reading to Remote Access
These new capabilities transform the Kindle from a simple reading device into a potential thin client for a self-hosted ecosystem. With the proxy mode, users can now connect KOReader directly to services like Calibre for ebook management, Wallabag for article archiving, or Audiobookshelf for audiobook streaming.
The update also enables Tailscale SSH by default, a significant security improvement over the previous reliance on USB networking SSH with its well-known default credentials. This makes remote administration of the Kindle itself far more secure and practical for ongoing tinkering.
While using a Bluetooth keyboard with the kterm app to SSH into other tailnet devices remains a niche pursuit, it exemplifies the expanded possibilities. The Kindle is no longer just a passive reader; it becomes an active, if unusual, node in a secure, private network.
The KOReader Plugin: Extending the Ecosystem
For users who don't need full device-level Tailscale access, developer Victoria Riley Barnett has created a dedicated Tailscale plugin for KOReader. This plugin automates the creation of the proxy interfaces needed to reach content servers, and it extends support beyond the Kindle to include Kobo and PocketBook devices.
Installation involves copying the plugin into KOReader's directory, triggering an install from the app's menu, and providing an auth key. Once configured, KOReader can use the proxy at 127.0.0.1:1055 (SOCKS5) or :1056 (HTTP CONNECT) to reach tailnet services.
The plugin also integrates well with a SyncThing plugin for KOReader, allowing for more advanced synchronization workflows. This demonstrates a growing ecosystem around making e-ink devices more capable and connected.
Broader Context: Repurposing E-Readers
This development fits into a larger trend of repurposing old or specialized hardware. As noted by WIRED, Kindles can be transformed into smart home displays, literary clocks, or Spotify controllers. These projects require varying levels of technical skill, but they all share a common goal: extending the life and utility of a device beyond its original design.
The Tailscale update is particularly compelling because it adds a secure networking layer to these projects. A Kindle turned into a smart home display could now securely pull data from a home server over a tailnet, rather than exposing services to the public internet.
Getting Started and Caveats
This remains community-driven software running on a device that Amazon actively discourages modifying. Patience is required. The TUN mode, in particular, is dependent on the specific Kindle model and its kernel version.
For those ready to experiment, the process starts with a jailbroken Kindle running the KUAL launcher. The updated Tailscale KUAL app can be found on GitHub, and the KOReader plugin is available from its own repository. Proper configuration of auth keys and proxy settings is essential for a smooth experience.
The result is a remarkably capable, low-power, long-battery-life device that can securely connect to a private network. It's a testament to the ingenuity of the open-source community and a glimpse into the future of edge computing on unconventional hardware.
Related News

UNA GPS Watch Introduces Repairable, USB-C, Developer-Friendly Design

Anthropic CEO Amodei Clarifies Stance: No Ban on Open-Weight AI, But Fears Chinese Dominance

$500 RL Fine-Tune of 9B Model Beats Frontier AI on Catalog Review

Anthropic CEO Clarifies Stance: No Ban on Open-Weight Models, but Safety First

AI Companies Destroying Rare Books: A New Ethical Crisis in Training Data Sourcing

