So e.g. if you use "log in with Google" on a web site, Google now has access to your account too (if they behaved badly or were compromised).
Spreading SSO auth everywhere gives the SSO provider login access to absolutely everything you have.
You are delegating authentication, so your delegated authenticator can authenticate anything they want.
I feel like a large number of people adopting SSO/IAM systems don't fully understand this. If they do understand and are making a cost/benefit based choice to do this that's one thing, but... I think people should understand.
- Tailnet traffic needs to be associated with an approved device key
- Tailnet device addition needs to be signed by the offline key of another approved device
If a compromised control plane and/or SSO provider can add and approve devices on their own then the security architecture of Tailscale would be fundamentally broken. I wouldn't even call it end-to-end encrypted.