From my read of the article it's mainly from the peer to peer nature of the setup. With Tailscale and wireguard you know where traffic is coming from and where it is going as it's not going through a central gateway.
You also can find out it's VPN data as it isn't tunnled over https or using any other masking methodology.
I belive you wouldn't find anything out about the data inside the wireguard tunnel just the wireguard tunnel metadata.
You also can find out it's VPN data as it isn't tunnled over https or using any other masking methodology.
I belive you wouldn't find anything out about the data inside the wireguard tunnel just the wireguard tunnel metadata.