Tailscale Authentication for Minecraft
tailscale.com
tailscale.com
Does anyone know whether they have measures in place to protect against IP spoofing?
Background: The OP reminded me of innernet (a Tailscale alternative) which was presented here on HN last year[1] and which is – at least in principle – vulnerable to IP spoofing[2] because it assumes incoming IP packets (with a WireGuard IP address as "source") must originate from WireGuard's wg0 network interface and cannot e.g. originate from eth0 – which, unfortunately, is not the case on most systems.
As far as I can tell from briefly looking at tsnet[3] (which is what their authentication proxy[4] uses under the hood), tsnet runs WireGuard in user space(?), so this should prevent IP spoofing. Can anyone confirm this?
[0] https://tailscale.com/blog/grafana-auth/
[1] https://news.ycombinator.com/item?id=26628285
[2] https://github.com/tonarino/innernet/issues/26
[3] https://github.com/tailscale/tailscale/blob/main/tsnet/
[4] https://github.com/tailscale/tailscale/tree/main/cmd/proxy-t...
The Tailscale client its self will automatically drop any packets that arrive over the tunnel with an unexpected IP address or protocol number (TCP, UDP, ICMP only).
innernet does exactly that but that doesn't help with spoofed packets arriving through some other network interface, as long as you don't explicitly tell your server (in this case Minecraft) to listen exclusively on wg0.
Hence my question.
Tailscale runs wireguard in the userspace and their clients consume packets directly out of the WireGuard tunnels before passing them onto a single Tailscale virtual interface. At no point is the Tailscale wireguard tunnel attached directly to a virtual interface, the Tailscale client inspects every packet moving in either direction first. I would strongly recommend reading up on how Tailscale handle ACLs, I think you’ll find it enlightening.
I can’t make any comments about Minecraft’s ability to detect spoofed packets, like you say that depended on the servers setup. But at point it’s no longer a Tailscale problem, Tailscale can only protect you from stuff sent over Tailscale. You want protection from the internet, you need to look else where.
Only cryptographically valid packets are accepted, and then we only return peer identity information for flows from said authenticated & authorized packets.
> By setting the whitelist setting to 127.0.0.1, you only allow connections from the Grafana authentication proxy to be able to bypass Grafana’s normal authentication mechanisms.
Since the proxy runs WireGuard in user space it will take care of assigning the IP addresses itself (after successful authentication), meaning no IP address spoofing or network interface "confusion" is possible.
(you might ask why we don't use the rp_filter sysctl for this; unfortunately linux has a broken precedence order where loose filtering overrides strict filtering, so even if we ask for strict behavior for tailscale0, if the systemwide default is loose, we get the insufficient loose behavior - so we implement RPF by hand in netfilter instead, sigh)
[0] https://github.com/GeyserMC/Geyser
Also, not encouraging it, but disabling authentication allows players with pirated copies of MC to play on the server
Wait, it's actually a good idea. Please put everything from Meta/Facebook behind a mandatory VPN so that I have zero chance of accidentally stumbling upon it.
With Tailscale, you just need to trust that Tailscale works, which seems like a much better bet given WireGuard's simple-and-auditable code plus the quality of Tailscale's dev team working on top of that.
After chatting a bit more he eventually felt bad and placed about a hundred chests filled with diamond armor and weapons before leaving, but that doesn't really remove the sting of having your personalized base destroyed and killed the challenge for the game.
We haven't played again since this year. At least now I know how to set up a cronjob to back up our world daily :P
Edit dug it out of my old emails, it was actually actually much longer than 6 years ago! The host was Phoenixerve, seems they don't exist anymore.
I’m sure a lot of parents would appreciate it being easier, with an in-app purchase of VPN, or similar access to safe, self hosted game play.
However do I get a bit of a buzz seeing my child open console and get the process ID then go to terminal and kill the flakey Minecraft app when it crashes. Requested for server reboots and grumbles at server RAM allocation etc. Maybe it being hard is actually a win.
Edit dug it out of my old emails. The host was Phoenixerve, seems they don't exist anymore.
And it 100% works. We're in the middle of rolling out Tailscale at our company because I and other people here had tried it personally for non-business use cases. FWIW this is also the path we took for the Outlook iOS/Android apps in the early days (and pre-Microsoft acquisition). Let people learn to love it, and then they'll want to bring it to their jobs.