← Back to context

Comment by Zambyte

2 days ago

It may still be sensible if you only expose it to private networks.

So could this safely be used on Tailscale then ? I’m very curious though also a bit paranoid.

  • > So could this safely be used on Tailscale then ? I’m very curious though also a bit paranoid.

    You may as well just use tailscale ssh in that case. It already disables ssh encryption because your connection is encrypted with WireGuard anyway.

  • It could safely be used on public internet, all this fearmongering has no basis under it.

    Better question is 'does it have any actual improvements in day-to-day operations'? Because it seems like it mostly changes up some ciphering which is already very fast.

    • > It could safely be used on public internet, all this fearmongering has no basis under it.

      On what basis are making that claim? Because AFAICT, concern about it being less secure is entirely reasonable and is one of the big caveats to it.

      1 reply →

    • I'm not fear mongering. I'm just saying

      - IF you don't trust it

      - AND you want to use it

      => run it on a private network

      You don't have to trust it for security to use it. Putting services on secure networks when the public doesn't need access is standard practice.

      2 replies →