Post B6FqZ6hkE5aH7dsGyO by 9pfs@tilde.zone
(DIR) More posts by 9pfs@tilde.zone
(DIR) Post #B6FmxhPkzYAq6pvpR2 by privateger@plasmatrap.com
0 likes, 0 repeats
Tailnet Lock is very neat :floof:
(DIR) Post #B6Fn22kHcpQbQObWHA by privateger@plasmatrap.com
0 likes, 0 repeats
Tailnet Lock lets you verify that no node joins your Tailscale network (known as a tailnet) unless trusted nodes in your tailnet sign the new node. With Tailnet Lock enabled, even if Tailscale were malicious or Tailscale infrastructure hacked, attackers can't send or receive traffic in your tailnet.
(DIR) Post #B6FqZ6hkE5aH7dsGyO by 9pfs@tilde.zone
0 likes, 0 repeats
@privateger may I give unrelated information that may help anyone wanting to prevent the tailscale control plane from being able to influence their network at all? don't want to do so without consent since it can be rude to do so
(DIR) Post #B6FqZ6t5XuergpBKee by privateger@plasmatrap.com
0 likes, 0 repeats
@9pfs@tilde.zone assuming you're talking about headscale: it does solve a similar problem, but i think there's a lot of value in tailscale "just working"
(DIR) Post #B6Fr6EARV5OdpA5gES by 9pfs@tilde.zone
0 likes, 0 repeats
@privateger not that, just that tailscale by default/in all states where it's allowed to do firewall modifications (which is any case where the --firewall-mode= setting is set to default) will allow all traffic in on the tailscale interface, in theory making you a single bad/malicious ACL update away from things meant to never be accessible from other machines being reachable, and that it may be a good idea to, depending on environment, remove tailscale's firewall editing privileges (it should run fine even without them) and instead manually create any amount from "none" to "all but the accept all" of tailscale's normal rules yourself to get a similar result with better securitynot sure if tailnet lock makes ACL updates more secure or something, but regardless, it can be nice to be able to manage firewall rules for all interfaces in the same place and not have to ask the question "wait, what if that external service forgets how to tell my device not to expose my (example) retro computing telnet server meant for LAN use to servers that run non-friendly software"hope I haven't been annoying at all by sending this