You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
So, as part of the hardening process of NixOS, I think tcpcryptd should be enabled by default - it encrypts TCP connections if it's talking to another tcpcryptd-enabled server, otherwise it falls back to standard TCP connections.
The text was updated successfully, but these errors were encountered:
I think tcpcryptd is a fantastic idea in principle but I'm -1 on enable-by-default. IMHO daemons that rewrite network traffic to that extend should be opt-in (principle of least surprise).
On top of that I'm not convinced that exposing another daemon written in c to the Internet is a great idea :)
So, as part of the hardening process of NixOS, I think tcpcryptd should be enabled by default - it encrypts TCP connections if it's talking to another tcpcryptd-enabled server, otherwise it falls back to standard TCP connections.
The text was updated successfully, but these errors were encountered: