Windows has APIs (named pipes, DCOM (eww) and such) that allow authenticated local access to services. Unixes have unix sockets.
Windows has APIs (named pipes, DCOM (eww) and such) that allow authenticated local access to services. Unixes have unix sockets.
(I don't know anything about Tailscale so I'm just going on first principles.)
They actually approximate this functionality in the Windows implementation: It checks netstat to enforce that incoming TCP connections are from the expected Windows user! https://github.com/tailscale/tailscale/blob/2a991a3541ae5d56...
That's why we were happy with the solution they implemented as a stopgap, until they could switch to named pipes (which there is now an open PR for).
It feels like there could still be a TOCTOU issue there, but it'd be difficult to use.
All the major cloud get this IMO entirely wrong with their services that issue secrets to instances (e.g. AWS IDMS).