logoalt Hacker News

jon_adleryesterday at 7:28 PM1 replyview on HN

Isn’t there separation of the control and data planes? I don’t think Tailscale get to see any of your network traffic.


Replies

nickburnsyesterday at 7:38 PM

They need to know how/where to route your outbound traffic. That inherently includes plaintext DNS, TLS handshakes, and otherwise plaintext traffic (like HTTP for example).

Anybody wanting to see what Tailscale is able to see can simply sniff any router interface passing outbound traffic before it enters the WireGuard tunnel interface.