An issue with his remote setup is that the remote VPS decrypts packets from the remote laptop, then re-encrypts them for the LAN — this means that the remote VPS can see the plaintext of all those packets. He’ll need to layer TLS or something similar, or run Wireguard over Wireguard.
akerl_|4 months ago
devsda|4 months ago
There's the private CA route but its a pain to setup the certs on all (mobile) devices and Android makes it very scary and hard.
ggpsv|4 months ago
age123456gpg|4 months ago
bronco21016|4 months ago
scrps|4 months ago