26 ms·
The Tailscale VPN client, the same one which runs on other devices, is compiled to WASM. It handles all of the key exchanges to connect to the tailnet. The SSH
by dgentry 4y ago
The Tailscale VPN client, the same one which runs on other devices, is compiled to WASM. It handles all of the key exchanges to connect to the tailnet. The SSH session is running as a WASM Tailscale client.
The browser, opening connections from within the browser engine, doesn't have the keys for SSH or VPN access.
- ikiris 4y agocitation needed
- shp0ngle 4y agoIt doesn’t have the keys, but it can inject any javascript and do whatever the user can do.
- Spivak 4y agoTo me it seems they've taken all precautions they can reasonably take -- "what if the user installs a keylogger" isn't fixable by anyone.
- gunapologist99 4y ago"Installing a keylogger" is a vast oversimplification, even if it is outside of their threat model. Installing almost anything in your browser is usually a matter of a couple of clicks.
- ithkuil 4y agoLike intercepting your oauth token next time you login into SSO and then use that to access your tailnet. This was true even before this new feature. The new threat model is entirely psychological.
- vngzs 4y agoSounds like about "as good as this gets" if you happen to want to do this in browsers. Good job.
- Asmod4n 4y agoAnd then the addon intercepts the loading of the Wasm code, injects it’s own payload into it and has access to the keys.
- lxgr 4y agoWhat keys? I think the implementation does not use regular SSH keys for SSH authentication, but rather something custom (I believe traffic to port 22 on each SSH enabled client is intercepted and the daemon handles authentication itself).
- lxgr 4y agoFor the downvotes: Am I misunderstanding Tailscale's implementation? I'm not commenting on whether it's a good or bad idea, but we should at least be talking about the same thing.
- fulafel 4y agoThe wasm code runs in the browser, hence the keys live in browser memory, so the browser has access to the keys.