I can now go to sleep without having to worry about random bots trying to mine crypto on my machines. To add to the goodness, one does not have to worry about either SSH-keys or remember cryptic passwords.
FWIW, setting up something like tailscale is remarkably simple (I'm using PHP here to keep it simple):
In sshd_config:
AuthorizedKeysCommand /auth_ssh %u
AuthorizedKeysCommandUser nobody
And in auth_ssh, verify that the user is allowed to connect to that server, then look it up on github (my public keys: https://github.com/withinboredom.keys).If you want to allow any github user you allow to connect various permissions, check out libnss-ato.
These are all 1 or 2 lines of configuration and are not hard. You just have to know they exist.
Regarding the strangeness; yes I was lazy and had password based ssh and was in constant fear that someone might pop my box.
I believe they are all based upon variations of the same java ssh library and exhibit the same behavior. They all connect to tailscale ssh using 'none' authentication but after connecting don't display anything which means I can't get the URL tailscale ssh presents to do its authentication.
Edit: I was just able to work around the issue by installing Termux and using openssh in that environment to do my initial ssh authentication. Afterwards my normal ssh app works.
I was just able to work around the issue by installing Termux which provides a small Linux environment on your phone. I was able to use openssh in the Termux environment to connect and get the authentication URL. After that my preferred ssh app can connect without issue.