Hacker News new | ask | show | jobs
by nottorp 169 days ago
> An attacker with local root can just extract the wireguard keys from process memory, or use the TPM to decrypt the state file like Tailscale would.

That was my point :)