It’s been an absolute gamechanger.
It’s been an absolute gamechanger.
It’s end to end encrypted, and with tail lock enabled, nodes can not be added without user’s permission.
I didn’t start with tailscale because the only way you could log into it was with Google or GitHub or something. I don’t trust Microsoft or Google with auth for my internal network. I thought about running Headscale but Nebula was faster/easier for me.
There's also potential for malicious updates to compromise a network (as there is with most software unless you're auditing the source for each update).
E2EE is only as meaningful as where the keys reside, and how easily those keys are abused.
The metadata is generally public information, I don’t care about that.
The malicious updates and key abuse are more concerning. It’s true for all software, and probably better done with OS, like on iOS.
The VPN could steal the keys, but that’s a lawsuit!
But with a malicious update, they could ship them to their infra, targeting some users. The product then becomes malware!
the docs are good. when creating the initial CA make absolutely sure you set the CA expiration to 10-30 years, the default is 1 which means your whole setup explodes in a year without warning.
totally different use case.