@mooroobee @ElonMusk Yep.
| Blog | https://blog.fimpern.de/about/ |
| Blog | https://blog.fimpern.de/about/ |
When you use Tailscale, we can't see your traffic - but we are responsible for distributing the public keys for your tailnet. What if we maliciously added new nodes to your network?
With tailnet lock, you don't have to trust us.
Introducing tailnet lock: a new security feature where your nodes verify the public keys distributed by the coordination server before trusting them for network connectivity.
Users sometimes ask us, “How can I trust Tailscale?” From the beginning, we’ve tried to make it so you don’t have to, by architecting our infrastructure with security and privacy in mind. When you use Tailscale, your data is end-to-end encrypted. Tailscale doesn’t have the private key, so we can’t see your traffic. While Tailscale can’t observe the data transiting your tailnet, we are responsible for managing the control plane, where our coordination server distributes public keys and settings for your tailnet.