@elb Totally got it, and am with you on that. I modified the systemd service file so it runs as a non-root user and have it heavily firewalled.
Incidentally, tinc has some similarities but is specifically targeting only private installations (no global network there). Yggdrasil can be used as a private VPN also but obviously it's targeting bigger things.