Hacker News new | ask | show | jobs
by db48x 119 days ago
No, that’s not quite true. The wireguard tunnels that the Tailscale daemon creates only go to your own machines. Nothing going through those tunnels goes to or is seen by Tailscale the company. Sometimes those tunnels go through a proxy (especially when you’re afflicted by CGNAT), but the proxy sees only encrypted traffic.
1 comments

So how does the proxy know where to proxy packets to?
The tailscale client on one of your computers tells it the address of your other computer.