3 ms·
The concern I have with these types of solutions (meaning Tailscale, Firezone, etc.), is that I need to trust the provider not to mess up or maliciously exchang
by taekwondo123 2y ago
The concern I have with these types of solutions (meaning Tailscale, Firezone, etc.), is that I need to trust the provider not to mess up or maliciously exchange keys with rouge devices. Is this the case with Firezone as well?
I see that tailscale addresses this now somewhat:
https://tailscale.com/kb/1226/tailnet-lock https://tailscale.com/kb/1226/tailnet-lock
- psd1 2y ago> maliciously exchange keys with rouge devices Companies are slow to respond to the growing threat from adversarial make-up brushes.
- RsmFz 2y agoI live by but two rules, private keys stay on the storage device they're first saved to, and makeup stays with the first person to use it.
- RsmFz 2y agoFirezone employee here. I believe we have an idea to let customers sign their keys so that they don't need to trust our portal not to rewrite keys. This is probably the same idea Tailscale hit on. (I can't find this idea in the issue tracker and I don't think it's on the roadmap yet, but we've discussed it.) Unfortunately there is a big convenience-security tradeoff, managing your own keys and certs is a lot of work.
- aborsy 2y agoWhy somewhat? The client has to sign the key, and Tailscale can’t add public keys to the network.