Skip to content
Discussion options

You must be logged in to vote

Traffic sent over Yggdrasil is always encrypted, and in the case of a tls:// peering, it's actually doubly-encrypted (once as E2E for the destination, once for the TLS link). The only thing sent over plaintext in a tcp:// peering is Yggdrasil protocol traffic, but those are also cryptographically signed to prevent tampering.

I think your AI has probably missed this nuance, but we keep tcp:// around because there are some lower-end devices where the processing cost of TLS is quite high.

Replies: 3 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by slrslr
Comment options

You must be logged in to vote
2 replies
@majestrate
Comment options

@sdgathman
Comment options

Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants