>>> We would like to thank Anthropic and Ada Logics for reporting this issue. it seems anthropic also use tailscale or it's just being discovered by the mythos model?
TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
41–50 of 157 posts
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#42Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#43I'll stick to my 100% self-hosted Wireguard setup, thank you very much.
Why not tailscale plus head scale for self hosting?
I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point.
The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor.
I never understood the popularity of Tailscale, though that is on me. I'm sure it is a great product, I just never tried it, do not seem the target audience.
What confuses me is the often accompanying, sometimes aggressive anti-selfhosting stance in these sorts of threads. I do not see this in other topics, e.g. someone mentioning they run Jellyfin isn't met with "why not Plex?". Where does that come from? We are on HackerNews, not ProductShillNews, aren't we? I guess self hosting Wireguard is too boring to warrant any further discussion? The VPN equivalent of a Toyota Corolla.
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#44I'll stick to my 100% self-hosted Wireguard setup, thank you very much.
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#45I’m a heavy Tailscale user, so I do trust them quite a bit, but I never used the Tailscale SSH feature. I feel like OpenSSH’s security record is pretty unbeatable, not sure why I’d swap over for such a security-sensitive tool.
I've used it before to access my tailnet machines through a browser on a machine I can't download software on.
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#46pure logic error, the undergoing tailscale rust rewrite can't help this too:)
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#47> "Tailscale SSH now rejects usernames with leading dashes." Really? That's the fix? A proper fix is to use "--" to separate arguments.
“--“ doesn’t work on all versions of getent. A better fix is to call “getent passwd” with no user controlled arguments and then parse the resulting list. This gets rid of the input sanitization problem entirely.
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#48Earlier quoted context omitted.
Why not tailscale plus head scale for self hosting?
I do not understand this rebuttal. I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point. The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor. I never understood the popularity of Tailscale, though that is on me…
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#49Earlier quoted context omitted.
I do not understand this rebuttal. I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point. The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor. I never understood the popularity of Tailscale, though that is on me…
I think Tailscale is popular because of how plug and play it is for most people. Although the main reason I use it over self hosting wireguard is the NAT busting it does, which has so far worked flawlessly for me with no setup aside from installing on both devices. There is nothing wrong with self hosting wireguard, but it doesn't actually do the same job as tailscale.
Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
#50Earlier quoted context omitted.
Why not tailscale plus head scale for self hosting?
I do not understand this rebuttal. I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point. The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor. I never understood the popularity of Tailscale, though that is on me…