From "The New Internet" on @tailscale's blog:
https://tailscale.com/blog/new-internet
"...and today you have or don’t have a TLS cert, tomorrow you’ll have or not have Tailscale"
But a browser's Secure Context[1] depends on TLS. Any thoughts on pushing for change there? Can Wireguard be an alternative for TLS and get a secure context?
[1] https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts
@teleclimber @tailscale Not sure I buy Tailscale's vision but it's definitely cool they have one. PKI needs to die, and I expect the CAB Forum members to fight that tooth and nail but someday alternatives to PKI will be considered secure in the browser, even if we have to fork them to get there.
@ocdtrekkie @tailscale Yeah I don't know what it's going to take but I really want that to happen. I'm wiriting a blog on connectivity when self-hosting and the need for TLS pushes everything into a crappy compromise.
As for them, I think they're on the right track but I don't see one company providing that for all. It needs to be based on open specs. Still I hope they can help us all get there, and if they make a chunk of change along the way good for them.