Earlier quoted context omitted.
> Another concern I have is whether a compromise of Tailscale's own infra could let an attacker just add itself to my network. Apparently the "Tailnet Lock" feature mitigates this, but it is off by default. Yeah, we use "tailnet lock" to sort of cover that. AFAIK its the only option available. I say "sort of" because "tailnet lock" is a bit half-assed in its design and implementation. For example, you cannot sign new…
Comically you can sign Tailnet lock from iOS, but it’s an insane workflow. You need to generate a QR code then scan it from the signing mobile device, which opens a secret menu option to sign (fine just brings up a confirmation dialog). Incredibly annoying but perhaps more secure vs the threat of randomly tapping at prompts
Interesting, thanks for pointing out the insane workflow.
Although looking around, footguns still remain in terms of relying too much on iOS and Tailnet Lock, e.g. https://github.com/tailscale/tailscale/issues/20475