Live data from Hacker News

TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

tailscale.com

41–50 of 157 posts

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#41

>>> We would like to thank Anthropic and Ada Logics for reporting this issue. it seems anthropic also use tailscale or it's just being discovered by the mythos model?

I presume Ada Logics has access to Anthropic's Mythos model via Project Glasswing, and Ada Logics discovered this exploit during their vulnerability research.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#42
post #24

I'll stick to my 100% self-hosted Wireguard setup, thank you very much.

haha self hosted wireguard, an opportunity to find out AllowedIPs: 0.0.0.0/0 does the opposite of what you think it will do

[dead]

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#43
post #24

I'll stick to my 100% self-hosted Wireguard setup, thank you very much.

Why not tailscale plus head scale for self hosting?

I do not understand this rebuttal.

I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point.

The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor.

I never understood the popularity of Tailscale, though that is on me. I'm sure it is a great product, I just never tried it, do not seem the target audience.

What confuses me is the often accompanying, sometimes aggressive anti-selfhosting stance in these sorts of threads. I do not see this in other topics, e.g. someone mentioning they run Jellyfin isn't met with "why not Plex?". Where does that come from? We are on HackerNews, not ProductShillNews, aren't we? I guess self hosting Wireguard is too boring to warrant any further discussion? The VPN equivalent of a Toyota Corolla.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#45
post #11

I’m a heavy Tailscale user, so I do trust them quite a bit, but I never used the Tailscale SSH feature. I feel like OpenSSH’s security record is pretty unbeatable, not sure why I’d swap over for such a security-sensitive tool.

I've used it before to access my tailnet machines through a browser on a machine I can't download software on.

I just don't use stranger's machines to access my personal stuff. Possibly compromised stranger's machines. I don't see the benefit about that, as I have more laptops than I need.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#47
post #7

> "Tailscale SSH now rejects usernames with leading dashes." Really? That's the fix? A proper fix is to use "--" to separate arguments.

“--“ doesn’t work on all versions of getent. A better fix is to call “getent passwd” with no user controlled arguments and then parse the resulting list. This gets rid of the input sanitization problem entirely.

Are there any actual systems that can run Tailscale and that have faulty getent?

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#48

Earlier quoted context omitted.

Why not tailscale plus head scale for self hosting?

I do not understand this rebuttal. I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point. The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor. I never understood the popularity of Tailscale, though that is on me…

I think Tailscale is popular because of how plug and play it is for most people. Although the main reason I use it over self hosting wireguard is the NAT busting it does, which has so far worked flawlessly for me with no setup aside from installing on both devices. There is nothing wrong with self hosting wireguard, but it doesn't actually do the same job as tailscale.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#49

Earlier quoted context omitted.

I do not understand this rebuttal. I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point. The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor. I never understood the popularity of Tailscale, though that is on me…

I think Tailscale is popular because of how plug and play it is for most people. Although the main reason I use it over self hosting wireguard is the NAT busting it does, which has so far worked flawlessly for me with no setup aside from installing on both devices. There is nothing wrong with self hosting wireguard, but it doesn't actually do the same job as tailscale.

NAT busting is a great point.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#50

Earlier quoted context omitted.

Why not tailscale plus head scale for self hosting?

I do not understand this rebuttal. I also run self-hosted Wireguard. Initially on a Debian box, nowadays it is integrated into my router (admittedly, this is closed source). For around 6 years at this point. The whole thing could not be easier and simpler. It has never randomly broken on me. It is fast. It is free. There is no middle man, no vendor. I never understood the popularity of Tailscale, though that is on me…

How do I install wire guard on my mom's Apple TV?
Post reply on HN