5 ms·
Yeah, but e.g. no rsh (or telnet!) on macOS. It's likewise a bit silly that we had to add TLS support to Tailscale: https://tailscale.com/blog/tls-certs/ https
by bradfitz 4y ago
Yeah, but e.g. no rsh (or telnet!) on macOS.
It's likewise a bit silly that we had to add TLS support to Tailscale: https://tailscale.com/blog/tls-certs/ https://tailscale.com/blog/tls-certs/
But we want to interoperate well with the clients people already have (browsers, their system ssh client, etc...)
- throwaway894345 4y agoIs there an option to avoid double encryption on systems that do have e.g. rsh?
- dangerlibrary 4y agoI might be misunderstanding the question but ... just use rsh?
- throwaway894345 4y agoI think for the same reasons I wouldn't "just use ssh" over tailscale--I don't want to have to manage an sshd that doesn't require key or password auth but listens over tailscale (and nothing else!). Basically, what I want is for tailscaled to be my rshd (appropriately configured for connections over tailscale network only, etc) or in other words to avoid double-encryption (it's not the end of the world, but ideally we don't need to doubly-encrypt).
- structural 4y agoDouble (or more) encryption ends up happening a lot in larger networks not for technical reasons but for policy ones. This is unsurprising, because it is used for different purposes in different layers of the stack. It is not at all a black and white state of "encrypted" vs. "not encrypted". For example, in one organiztion I've worked with, Wireguard (generally, including Tailscale) is approved for restricting connections only to authorized network devices/users and that data maintains integrity in transit, but is not approved for protecting the confidentiality of sensitive information. Connections which access specific resources are required to be encrypted at the application level using a mechanism which has been approved for that information type (given a specific threat model). So you could transmit very small amounts of data over TCP/IP, over a Tailscale network, using a set of pre-shared, one-time pads. And you might actually want to do this! It's really not ridiculous, but you do need to assess whether you really do have a threat model that needs it.
- raggi 4y agoAround the time I joined Tailscale, actually just before, I had a look at rsh with an eye in this direction. The problem is that rsh is very stale and unmaintained - even those versions that have had releases in recent years (e.g. GNU Inetutils) are very old inside - even if they've kept up with patches, they have not kept up with features e.g. modern user session construction. It also turns out that ssh the client, much more so than ssh the protocol, is really a key integration point and API that users end up needing. It has a broad feature set that turns up in use cases all over, many of which rsh does not handle.
- runjake 4y agoFWIW for those reading (I figure Brad already knows): echo "alias telnet=nc -v" >> ~/.zshrc && source ~/.zshrc
- apenwarr 4y agoAlas, the real “telnet” protocol has considerably more fanciness than nc. It’s just that the telnet cli command degrades into a simple line-oriented mode if it doesn’t see the telnetd init sequence.
- ithkuil 4y agoFor example window size negotiation
- runjake 4y agoTrue, but it handles 99% of the use cases of the people who lament the demise of telnet in macOS. :-) For the rest: brew install telnet
- Brian_K_White 4y agomacports please
- runjake 4y agoHere you go: sudo port install inetutils
- Brian_K_White 4y agoBetter. Thank you :)
- jackthetab 4y agoI read that in Chris Rock's voice. :-)
- oefrha 4y agoFrom the blog post on TLS support: > However, if your service doesn’t have a valid TLS certificate, despite the fact that your connection is encrypted using Tailscale, your browser will warn you that the connection is not secure (it’s doing the right thing—it doesn’t know about Tailscale!). So, to avoid confusing your users, you might want to provision a TLS certificate to validate your internal services. Browser warnings and user confusion aren’t the only consequence of not using HTTPS. The more concrete impact is that you lose access to a large and growing number of web APIs that are restricted to secure contexts. https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts/features_restricted_to_secure_contexts https://developer.mozilla.org/en-US/docs/Web/Security/Secure...
- bradfitz 4y agoYup! In fact, that was the very first sentence of the original GitHub bug about TLS certs: https://github.com/tailscale/tailscale/issues/1235 https://github.com/tailscale/tailscale/issues/1235 ... "Many new web APIs (eg: geolocation, sensors, http/2, etc) require a TLS certificate"
- pehtis 4y agoYou can still use telnet v1.9.4 on macOS. Just copy it from an old version of OSX (pre High Sierra). It still works fine on Monterey.