6 ms·
Analyzing the public hostnames of Tailscale users
- cperciva 5y agoMade-up words: lois, gimli, thopter I think this category is "pop culture references".
- yjftsjthsd-h 5y agoExtra funny that in the list under the chart these are separate lines: > Non-descriptive words: spike, slab, cardinal > Made-up words: lois, gimli, thopter > Pokémon: mewtwo, mew, bronzong Like... sort of valid groups, but not mutually exclusive.
- 2Gkashmiri 5y agoWhy is the "community server" only allowing 25 users and other stuff. Is that a hard requirement or just to deter users from rolling their own server?
- tyingq 5y agoIt appears to be a limit of 20 for the free tier, limited by the non-open-source hosted coordination server backend. There is "headscale", where you can self-host the backend. https://github.com/juanfont/headscale https://github.com/juanfont/headscale
- 2Gkashmiri 5y agoEverything in Tailscale is Open Source, except the GUI clients for proprietary OS (Windows and macOS/iOS), and the 'coordination/control server'. this is confusing. is the "control server" proprietary? is that headscale?
- tyingq 5y agoYes, the coordination/control server is closed source, and runs on Tailscale's servers. Headscale is a 3rd party, open source, self-hosted, replacement for that piece.
- 2Gkashmiri 5y agooh. this is great. thank you.
- Shish2k 5y agoAlso for anyone wondering, the desktop clients can be pointed to a custom control server (eg self-hosted headscale) relatively easily; but the android app needs to be edited / recompiled / sideloaded; and the iOS app can’t be pointed at a custom server at all :(
- xyzzy_plugh 5y agoI enjoy Tailscale, but their split-DNS approach for letsencrypt is a huge turn off. There's no need for my network topology to be exposed via certificate transparency logs.
- lilyball 5y agoWhat's the alternative?
- madjam002 5y agoPrivate PKI with Root CA
- egberts1 5y agoI made a little bash-only ditty on managing private CA https://github.com/egberts/tls-ca-manage https://github.com/egberts/tls-ca-manage
- easton 5y agoThe Caddy web server has a built in ACME compliant CA. Works well for a private CA, and it’s a couple lines in the config file.
- lilyball 5y agoThat requires modifying your OS trust store[1], doesn’t it? [1] And browser trust store if it doesn’t use the OS, and OpenSSL trust store if you use tools that don’t use the OS trust store, etc
- zokier 5y agoWhat do you see as the alternative? And isn't all this opt-in, you can run your own dns and do let's encrypt yourself if you prefer?
- jc__denton 5y agoThis is the one big downside to certificate transparency. Allowing anyone to ascertain private host names is far from ideal. The immediate counter is to, “run your own CA,” but that comes with its own headaches for small use cases.
- tailspin2019 5y agoI use wildcard LetsEncrypt certs for securing internal stuff which seems to solve this particular issue. Something like *.internal.mydomain.com - so that’s all that would appear in transparency logs. I guess this means you have to manage your own internal DNS mapping to your Tailscale IPs though rather than using Tailscale’s convenience split-DNS.
- cyounkins 5y agoWhy is the dataset so small? Surely there must be more than 312 Tailscale users who used tailscale cert?
- tailspin2019 5y agoI thought this seemed low too, but it’s a pretty new feature and if you’re the security conscious type already (by virtue of being a Tailscale user) you may already have your own certs setup for these internal hosts.
- spockz 5y agoInteresting. I’m using Tailscale with the split dns feature and my hosts don’t appear to be in the transparency logs. So which feature needs to be enabled to get exposed like this?
- zrail 5y agoThis happens when you turn on the HTTPS beta feature.
- infogulch 5y agoIf I can create a wildcard certificate for a domain by proving that I control DNS, why can't I use that cert as a "mini CA" to create valid certs that are a limited subset of the wildcard cert? Say I get a 90-day cert for *.example.com, and I want to use that to create a 30-day cert for a.example.com. I don't see how this would be abusable, and it would be nice for these scenarios where certs are used in a private network so you don't have to expose your internal hostnames to the world.
- wiml 5y agoThe short answer is: because client software doesn't implement that. The longer answer is: the certificate system absolutely does support issuing sub-CAs with "name constraints", which would let LE issue you, instead of a wildcard host certificate, an intermediate CA which you can use to issue host certs only in your own part of the name space. It solves this problem very neatly. However, see point 1 again: client support is lacking. OpenSSL and NSS handle it, IIRC the Windows and Android implementations are tolerable, but Apple's homegrown SSL implementation doesn't. (It's not even a new feature — it's in the original PKIX RFCs from, what, 25 years ago.) And without client support, CAs aren't going to do the work to be able to issue them, which means we're stuck with the far-less-secure approach of wildcard certs with shared (!) private keys, or unconstrained sub-CAs.
- infogulch 5y agoThanks, that makes sense. The only way I can see Apple making this change is if there were external pressure, which means implementing it without support for Apple products at first. Someone has to make the first move, and it won't be Apple. I did a bit of searching and it looks like this feature has been requested a few times on the LetsEncrypt community site, and this [1] is the best thread I think. Commenters there bring up another potential roadblock: aiui current regulatory requirements mean that there's a bunch of manual paperwork for every issued CA, name constrained or not. If anyone could automate and operationalize that process it would be LetsEncrypt. It would still be a lot of work, on the same scale as their initial (long, arduous) effort to automate issuance of leaf certs. Maybe a solution could be found by leaning on DNSSEC as a stronger validation of domain ownership than dns01. (As a side benefit, it would also be a small step towards eliminating the need for CAs in general.) [1]: https://community.letsencrypt.org/t/standardized-tools-for-automating-subordinate-name-constrained-cas/136969 https://community.letsencrypt.org/t/standardized-tools-for-a...