3 ms·
> If you're using only key-auth and have password auth disabled, I'm not sure why unauthorized attempts are a problem. See xz vulnerability for more details. I
by gabeio 2y ago
> If you're using only key-auth and have password auth disabled, I'm not sure why unauthorized attempts are a problem.
See xz vulnerability for more details. It’s about not trusting people with any of my ports/software (directly).
- papichulo2023 2y agoDid you vet all Tailgate infra? Because now your attack surface is way higher. Wouldnt surprise the xz is somewhere there as well.
- gabeio 2y ago> Did you vet all Tailgate infra? > I use the tailscale lock feature so not even tailscale themselves can add nodes to my network. https://tailscale.com/blog/tailnet-lock https://tailscale.com/blog/tailnet-lock https://tailscale.com/kb/1226/tailnet-lock https://tailscale.com/kb/1226/tailnet-lock