Lol i expected a text about protecting relays from mechanical or electric problems. You know those real mechanical relays we used to build computers of some years ago
I've got an electrical garage door opener, came with the house. We've been here 16 years and the relay has always been sticky: I have to bash the unit with a broom for it to work. One day I'll replace that damn relay.
> A leaked token enables connections, but not impersonations. The token is addressed to one specific endpoint's public key
So now the problem is moved to "how do you decide who to issue tokens to?", which every project must solve individually. It might sound like I'm being dismissive here but I think that's exactly the right approach.
The thing that surprised me running relays for robot fleets: relay was not the fallback, it was the common case. Hole punching fails a lot behind enterprise NAT.
Or found in just about every home appliance where mains voltage is switched by a CPU.
So now the problem is moved to "how do you decide who to issue tokens to?", which every project must solve individually. It might sound like I'm being dismissive here but I think that's exactly the right approach.
Tailscale seems better for controlling my own network?
https://xkcd.com/810/