Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cronos
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
cronos
9mo ago
There are some forks that are not compatible with regular wireguard, for example from wolfssl. Or just classic mTLS.
2.
▲
by
cronos
9mo ago
The macOS client uses the keychain by default, that's not changed here .
3.
▲
by
cronos
9mo ago
Good to know, my understanding of the macOS system APIs is fairly limited. I'm sure it's doable, with some elbow grease and CGO. We just haven't prioritized that variant of the client due to relatively low usage.
4.
▲
by
cronos
9mo ago
Ah, looks like another KB update is needed, thanks for calling it out!
5.
▲
by
cronos
9mo ago
On macOS we have 3 ways to run Tailscale: https://tailscale.com/kb/1065/macos-variants Two of them have a GUI component and use the Keychain to store their state. The third one is just the open-source tailscaled b
6.
▲
by
cronos
9mo ago
IIUC, it's a bit more nuanced: TPM stores hashes of various things like firmware in PCRs, and when creating keys in the TPM you can optionally bind the key to specific PCR values. But you also don't have to (and Tailscale doesn&#x
7.
▲
by
cronos
9mo ago
Not even that. An attacker with local root can just extract the wireguard keys from process memory, or use the TPM to decrypt the state file like Tailscale would. The only scenario where it helps is a local attacker who can read the state f
8.
▲
by
cronos
9mo ago
Nope, only Windows/Linux where TPMs exist.
9.
▲
by
cronos
9mo ago
There are two new-ish features in Tailscale that use TPMs: node state encryption ( https://tailscale.com/kb/1596/secure-node-state-storage ) and hardware attestation keys. Hardware key attestation is a yet-unfinishe
10.
▲
by
cronos
9mo ago
Yes, we use github.com/google/go-tpm/tpm2
11.
▲
by
cronos
9mo ago
Windows uses TPM for Bitlocker. A very common scenario where TPMs get reset is BIOS updates (when a TPM is implemented in firmware). AFAIK, Windows cheats here because it also manages BIOS updates. When an update happens, it takes extra ste
12.
▲
by
cronos
9mo ago
I'm one of the Tailscale engineers who built node state encryption initially (@awly on Github), and who made the call to turn it off by default in 1.92.5. Another comment in this thread guessed right - this feature is too support inten
13.
▲
by
cronos
2y ago
The tailscale client generates WireGuard key pairs, but only sends public keys to the control plane. The private keys remain on the device only. With only the public keys, tailscale control plane cannot snoop on your traffic.
14.
▲
Aggregator of all organizations helping Ukraine that accept donations
(pledgeukraine.org)
2 points
by
cronos
5y ago
|
1 comments
15.
▲
by
cronos
5y ago
Want to donate to help Ukraine but there are too many options? A group of volunteers (including myself) put together this aggregator site with structured organization info and some filtering options. You can skim through ~100 orgs quickly a
16.
▲
by
cronos
5y ago
You can un-register any of the keys when you're logged in. So if you lose one key, log in using the others and remove it. No need for a master key.
17.
▲
by
cronos
5y ago
PKCS#11 is a C API. It does not describe the wire format for talking to the actual hardware. To use PKCS#11 for a particular device, you need a module (shared library) to translate between the C API and the actual hardware. This module is u
18.
▲
by
cronos
5y ago
Mostly yes. It's a niche product with low demand and relatively high R&D costs, so margins have to offset that. There's probably also a bit of psychological biases at play, like: "if your HSM is 10x cheaper than everyone
19.
▲
by
cronos
6y ago
A "ton" of work may have been an exaggeration. Maintaining a CA (and dealing with cert rotation) is some work. Other things are indeed just a flag or config option (like jumphosts). But it takes work for a sysadmin/devops to
20.
▲
by
cronos
6y ago
There are a few differences between an OpenSSH jump host and Teleport: - you have to actively manage authorized_keys for every person using openssh; Teleport manages a PKI and can be backed by your existing SSO - it hard to restrict any giv
21.
▲
by
cronos
6y ago
Yes, but it's rarely how companies use OpenSSH because it takes a ton of work to set up. Teleport gives you all this functionality by default out of the box. So it's not inventing anything new, just provides better UX.
22.
▲
by
cronos
6y ago
The NATted device dials out to the bastion (a.k.a. proxy) and maintains a persistent tunnel. The proxy then sends all the connections to this device inside that tunnel.
23.
▲
by
cronos
11y ago
Without IPFS, pretty sure authorities can order to take down the repository and all of the forks.
24.
▲
by
cronos
11y ago
It seems like the author was in this thread. But you're right, re-posted my comment in a less aggressive form on the post itself.
25.
▲
by
cronos
11y ago
The code examples are quite non-idiomatic and have lots of issues, to be honest. - constant strings (defined as vars) as return values instead of the standard error type - not formatted - synthetic request's response body not closed -
26.
▲
by
cronos
11y ago
You can easily learn go by going through all the pages under "Learning Go" here: https://golang.org/doc/ and probably some practice projects. This book might be a good alternative but we can't know yet.
27.
▲
by
cronos
12y ago
Did you try comparing any of those to stdlib? I didn't hear people claiming that any of those you listed is idiomatic Go.
28.
▲
by
cronos
12y ago
Probably no. Author says that he uses IDs as keys. I can assume that they are 32 or 64 bit long. So even if they are 32 bits, you would need a 4GB slice to hold any potential key. Or make a dynamic array (well, slice) that would give even
29.
▲
by
cronos
12y ago
This model is called Communicating sequential processes. Comparison between actor model and CSP can be found here http://en.m.wikipedia.org/wiki/Communicating_sequential_proc...
30.
▲
by
cronos
13y ago
They called me back 6 month after first rejection. Going for on-site to London in a week.
More ›