3 ms·
If you're paranoid enough to think about the coordinator getting hijacked, you can also have each of the clients send up their logs to your splunk or whatever s
by chipsa 4y ago
If you're paranoid enough to think about the coordinator getting hijacked, you can also have each of the clients send up their logs to your splunk or whatever server, and correlate them together (double entry logging, anything that doesn't have a match is probably wrong). Should be able to do the same for DNS: anything that's not a ts.net domain getting queried against the tailscale coordinator server isn't right, etc.