3 ms·
The problem with the building block approach is that it usually compromises any supposed security advantages Wireguard may have. You get a supersecure bank safe
by throwaway294566 4y ago
The problem with the building block approach is that it usually compromises any supposed security advantages Wireguard may have. You get a supersecure bank safe where the key is handed to you in the baker's shop opposite if you ask nicely.
- cpach 4y agoI don’t believe that’s the case. However, the system on top of WireGuard cannot just spit out a key to the user and call it a day. The key (sorry…) is to make the system a) verify the identity of the users via an IdP (e.g. Okta or something similar) and then b) distribute short-lived keys, that can be revoked. If one reads how Tailscale handles user authentication and key rotation, one will notice that they have a solid system in place for handling the keys and the product is much more sophisticated than OpenVPN. I haven’t studied the approach of their competitors (e.g. Firezone) so I can’t comment on that. References/suggested reading: https://tailscale.com/kb/1028/key-expiry/ https://tailscale.com/kb/1028/key-expiry/ ⦁ https://tailscale.com/blog/tailscale-key-management/ https://tailscale.com/blog/tailscale-key-management/ ⦁ https://tailscale.com/customers/gini/ https://tailscale.com/customers/gini/ ⦁ https://tailscale.com/kb/1009/protect-ssh-servers/ https://tailscale.com/kb/1009/protect-ssh-servers/