Live data from Hacker News

Tailscale didn't stop the Hugging Face intrusion

tailscale.com

41–50 of 239 posts

Re: Tailscale didn't stop the Hugging Face intrusion

#41
post #20

> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

Glad to see companies owning responsibility and putting out a message without corporate PR spin

If you can't see the spin on corporate messaging it means it's working (and consequently, to stretch the metaphor, your wicket is in danger).

Re: Tailscale didn't stop the Hugging Face intrusion

#42

> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.

[flagged]

Re: Tailscale didn't stop the Hugging Face intrusion

#44

Quoting Tailscale: This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit Tailscale, and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will.

Next time we will - provided you further lock yourself into our ecosystem.

Re: Tailscale didn't stop the Hugging Face intrusion

#45

Humble bragging turned to marketing. Respect for the spin. Not using them, but been on my radar for some time and thinking of how to make something like that usable in my setup.

If you do any sort of homelabbing, it’s wonderful for making access from different machines easy and portable. Especially since you can leave it on and (unless you set an exit node) it will only route traffic meant for your tailnet through your tailnet, and use the internet otherwise.

Re: Tailscale didn't stop the Hugging Face intrusion

#46
Wow, this article is super smart marketing by tailscale. Not only do they list all the nice and expensive features, that can help in such a situation but they also show that someone at huggingface made a very stupid thing by writing a reusable auth key in an env file. Everyone using mesh VPNs like tailscale, netbird etc. knows that this is like leaving the keys right at the door.

Re: Tailscale didn't stop the Hugging Face intrusion

#47

Earlier quoted context omitted.

Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.

[flagged]

It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity.

I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it.

Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.

Re: Tailscale didn't stop the Hugging Face intrusion

#48

Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.

I lead the customer engineering org at Tailscale. We think this is a great idea and we're discussing internally potentially adding that to the console. In the meantime, if you'd like to get an assessment, please feel free to open a support ticket ( https://tailscale.com/contact/support?type=other&subject=sec... ) and we'll happily take a look

I've always found tailscale's json config a bit intimidating. I greatly appreciate the new UI that makes it easier to define rules, alas, both going to relevant docs straight from it and determining 'is this rule just lazy/bad/unsafe' is hard and frustrating most of the time.

That's where I'd like to see this sort of checkup. Yell at me please if i just said anyone can ssh as root from any node!

Re: Tailscale didn't stop the Hugging Face intrusion

#49
> One of those 136 credentials was a reusable Tailscale auth key, used to create new Tailscale CI (continuous integration, used for automated testing) nodes in their tailnet. The agent copied that key into a series of external sandboxes and used it, over several days, to enroll a total of 181 nodes into Hugging Face’s tailnet. Those nodes each received a Tailscale identity tag granting all the access a CI node would get.

This feels like an alerting opportunity. I wonder what the lowest friction way would be for Hugging Face to have alerts if 181 unexpected nodes were added to a tailnet.

Re: Tailscale didn't stop the Hugging Face intrusion

#50

> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

This article is just an ad / public-service-announcement for various paid Tailscale features, though?
Post reply on HN