Hacker News new | ask | show | jobs
by dvzk 1460 days ago
Requiring an administrator or other device to pre-authorize or manually approve a new device, by signing the new device key with a client signature key.

Why would you expect anything else? That’s like saying Wireguard or SSH servers should just accept any client. The purpose of mesh VPN controllers is to automate redundant key management, not to subvert the original security model.