> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.
Glad to see companies owning responsibility and putting out a message without corporate PR spin
Tailscale didn't stop the Hugging Face intrusion
41–50 of 239 posts
Re: Tailscale didn't stop the Hugging Face intrusion
#42> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
Re: Tailscale didn't stop the Hugging Face intrusion
#43Re: Tailscale didn't stop the Hugging Face intrusion
#44Quoting Tailscale: This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit Tailscale, and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will.
Re: Tailscale didn't stop the Hugging Face intrusion
#45Humble bragging turned to marketing. Respect for the spin. Not using them, but been on my radar for some time and thinking of how to make something like that usable in my setup.
Re: Tailscale didn't stop the Hugging Face intrusion
#46Re: Tailscale didn't stop the Hugging Face intrusion
#47Earlier quoted context omitted.
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
[flagged]
I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it.
Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
Re: Tailscale didn't stop the Hugging Face intrusion
#48Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.
I lead the customer engineering org at Tailscale. We think this is a great idea and we're discussing internally potentially adding that to the console. In the meantime, if you'd like to get an assessment, please feel free to open a support ticket ( https://tailscale.com/contact/support?type=other&subject=sec... ) and we'll happily take a look
That's where I'd like to see this sort of checkup. Yell at me please if i just said anyone can ssh as root from any node!
Re: Tailscale didn't stop the Hugging Face intrusion
#49This feels like an alerting opportunity. I wonder what the lowest friction way would be for Hugging Face to have alerts if 181 unexpected nodes were added to a tailnet.
Re: Tailscale didn't stop the Hugging Face intrusion
#50> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.