3 ms·
Am I the only one that has an issue with a VPN that I can't self host? Presumably if Tailscale get's PWN'd or subpoenaed then your network is breached no?
by throwaway92394 4y ago
Am I the only one that has an issue with a VPN that I can't self host? Presumably if Tailscale get's PWN'd or subpoenaed then your network is breached no?
- lvh 4y agoDepends on the kind of breach. Tailscale is extremely carefully designed to minimize that risk. Notably: Tailscale doesn't get your keys. (Granted: a compromised agent would still be a problem. It's a thing I have some plans for :-)) (Disclosure: I'm a (small) investor via Latacora's sibling fund, Lagomorphic.)
- moloch 4y agoNo, they don't have access to the Wireguard keys and everything is point-to-point. They'd have to push a backdoored software update to gain access (and this is a threat with any vendor product).
- soraminazuki 4y agoIIUC Tailscale controls key distribution, so you'd still have to trust them. However, it might still be possible to eliminate that need for trust by verifying peer connections out of band.
- bfm 4y agoA self hosted alternative we've been using for our infrastructure is innernet, which was discussed on https://news.ycombinator.com/item?id=26628285 https://news.ycombinator.com/item?id=26628285 last year
- cassianoleal 4y agoYou're certainly not the only one. There is headscale [0] if you're worried about that though. [0] https://github.com/juanfont/headscale https://github.com/juanfont/headscale
- cpuguy83 4y agoTailscale's data plane is [1] mostly p2p except for some cases where it doesn't work and it goes through an encrypted relay. So your data does not run through Tailscale servers. There is an oss [2]coordination server that does let you totally self-host. [1] https://tailscale.com/blog/how-nat-traversal-works/ https://tailscale.com/blog/how-nat-traversal-works/ [2] https://github.com/juanfont/headscale https://github.com/juanfont/headscale
- ignoramous 4y agoIf the tailscale control-plane is pwnd, outside of compromised ACLs (access controls) and DNS routes, I don't think it affects anything critical on the data-plane like passwords (because SSO) or private-keys since tailscale machine keys and node keys never leave the device: https://tailscale.com/blog/tailscale-key-management/ https://tailscale.com/blog/tailscale-key-management/
- aborsy 4y agoYes, Tailscale distributes public keys, and can add arbitrary nodes to anyone’s network. Not that they do it, but the possibility is there, and one has to account for risks.
- atsmyles 4y agoJust install wireguard yourself. With Bullseye on the RPi, it is easier than ever. There is a learning curve, but it is worth it.