I have a home server and I have some HTTP services running on it. I'm thinking if I should even bother with HTTPS, as I'm already using tail scale which should be peer-to-peer and encrypted. So I shouldn't worry about any men in the middle.

Am I missing something?

It just feels wrong to work with non-S HTTP :(

you are viewing a single comment's thread
view the rest of the comments
[–] 14 points 2 years ago (1 child)

It can still have issues with potential attacks that would redirect your client to a system outside of the VPN. It would prevent MitM but not complete replacement.

  • source
  • parent
  • hideshow 2 child comments