Hacker News new | ask | show | jobs
by cevn 14 days ago
Good point. I self host headscale but it also has the ssh feature, probably also insecure.
1 comments

Not necessarily, it's a clean room implementation. Even if leading dashes was known/documented/tested to implement they might have done it differently. And maybe it was an implementation detail that it was ever allowed, but that's a weird username, headscale implementation happened not to allow it, and nobody ever noticed the discrepancy.
How is that true if:

This project is not associated with Tailscale Inc.

However, one of the active maintainers for Headscale is employed by Tailscale and he is allowed to spend work hours contributing to the project. Contributions from this maintainer are reviewed by other maintainers.

Nice, this makes me feel a little better.