←back to thread

Stop Breaking TLS

(www.markround.com)
170 points todsacerdoti | 3 comments | | HN request time: 0s | source
Show context
arianvanp ◴[] No.46215864[source]
Complains about TLS inspection, yet fronts their website on the biggest and most widely deployed TLS introspection middle box in the world ...

Why do we all disdain local TLS inspection software yet half the Internet terminates their TLS connection at Cloudflare who are most likely giving direct access to US Intelligence?

It's so much worse as it's infringing on the privacy and security of billions of innocent people whilst inspection software only hurts some annoying enterprise folks.

I wish we all hopped off the Cloudflare bandwagon.

replies(7): >>46216030 #>>46216051 #>>46216089 #>>46217208 #>>46217601 #>>46221412 #>>46226753 #
phito ◴[] No.46216030[source]
I wish so too, same for all the self-hosters using tailscale...
replies(3): >>46216106 #>>46216426 #>>46216429 #
progbits ◴[] No.46216429[source]
Tailscale cannot passively observe traffic.

They could inject malicious keys into your config but would be hard to mask the evidence of that.

replies(1): >>46217158 #
treesknees ◴[] No.46217158{3}[source]
Would it be hard? I thought the point of tailscale was not having to manage or concern yourself with key distribution.
replies(1): >>46218087 #
1. newdee ◴[] No.46218087{4}[source]
Lookup the Tailnet Lock feature.
replies(1): >>46239239 #
2. yencabulator ◴[] No.46239239[source]
A feature in the client software they control, that you run as root, that auto-updates regularly?
replies(1): >>46254084 #
3. ◴[] No.46254084[source]