3 ms·
> They were on thin ice adding remote management (SSH) out of nowhere to what was supposed to be a VPN replacement. Now sysadmins and security have to deal with
by pilif 4y ago
> They were on thin ice adding remote management (SSH) out of nowhere to what was supposed to be a VPN replacement. Now sysadmins and security have to deal with users randomly shooting files around between devices.
historical note: Taildrop pre-dates Tailscale SSH by more than a year, so if you had concerns about Taildrop's functionality, those were valid way before ssh functionality was enabled.
Both Taildrop and Tailscale SSH are disabled the moment any ACL but the default (which allows everything to access anything which is what no enterprise runs with) is configured because their ACL feature allows only access but no denial, so if something isn't listed explicitly, it's denied.