“The WireGuard private key is stored in the memory of the Pritunl client background service and also in the WireGuard configuration file. WireGuard uses a connection-less design and this private key could be used by an attacker to hijack the connection even if multi-factor authentication is used. In high security environments it is important to consider that OpenVPN connections with multi-factor authentication will not have these weaknesses. For this reason the server will quickly revoke WireGuard keys of inactive clients to limit the possibility of this occurring”
Does anyone know how others like Tailscale address this issue?
[1] https://github.com/WireGuard/wgctrl-go [2] https://github.com/pritunl/pritunl/blob/f82528ff2b7250965faf...
Because these keys aren’t the short life, in-memory session keys[1], but auth keys. Knowing this single key effectively bypasses any MFA you may have.
Seems like Tailscale has 180 days by default[2], which feels a bit too long for a person who expects MFA to be more proactive than this. Sure you can change the default to 1 day, but how many users know it’s possible or would even think to change that?
Compare that with OpenVPN where you can force every single auth attempt to use a password plus TOTP code for instance.