I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it.
Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it.
Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
If you layer and segment correctly you can build atop a secure core and have some decent security.
Doesn't this apply to any application you use? How would it be different with plain wireguard?
Seriously ?
You do realise that of all the security tools on the planet, plain wireguard most likely has the smallest attack surface of them all, right ?
The problem here is as the other poster said. Tailscale is a security tool and yet the guys at Tailscale seem to be insistent on dumping everything INCLUDING the kitchen sink into it as a "feature".
That sort of attitude is not going to end well. You end up with a large bloated code base, which equals large attack surface.
Also a kinder tone in your comments would be more appreciated.
There is formal verification of the protocol and aspects of code:
https://www.wireguard.com/formal-verification/
The code is small enough that can be reviewed.