Tailscale didn't stop the Hugging Face intrusion
51–60 of 239 posts
Re: Tailscale didn't stop the Hugging Face intrusion
#52Quoting Tailscale: This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit Tailscale, and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will.
Next time we will - provided you further lock yourself into our ecosystem.
Re: Tailscale didn't stop the Hugging Face intrusion
#53[flagged]
Something about your comment comes across as AI to me. I can't really place my finger on it. It's too subtle for that. It's more the vibe of your entire comment that makes me feel it. Please, when commenting on HN, don't use AI to write your comments. You can afford to help keep this a human-centric place.
Re: Tailscale didn't stop the Hugging Face intrusion
#54Earlier quoted context omitted.
[flagged]
It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity. I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it. Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
Doesn't this apply to any application you use? How would it be different with plain wireguard?
Re: Tailscale didn't stop the Hugging Face intrusion
#55Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.
Was previously discussed here too: https://news.ycombinator.com/item?id=46501137
Re: Tailscale didn't stop the Hugging Face intrusion
#56I'm very sorry, but you can't blame a hammer for how it was used. You can't be blaming Tailscale for a customer's misconfigured setup.
Your mindset is the exact one responsible for these kinds of issues. Cybersecurity is as much a design and psychology problem as it is a technical one. The freaking article goes into detail about the dangers of defaults.
Re: Tailscale didn't stop the Hugging Face intrusion
#57Earlier quoted context omitted.
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
[flagged]
It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews.
The security audit report, which you perhaps imagine to be a long list of vulnerabilities... doesn't look like that. It says we don't have a long list of vulnerabilities. The security bulletins are all here: https://tailscale.com/security-bulletins
Re: Tailscale didn't stop the Hugging Face intrusion
#58> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.
This article is just an ad / public-service-announcement for various paid Tailscale features, though?
Re: Tailscale didn't stop the Hugging Face intrusion
#59Earlier quoted context omitted.
It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity. I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it. Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
> I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it Doesn't this apply to any application you use? How would it be different with plain wireguard?
Seriously ?
You do realise that of all the security tools on the planet, plain wireguard most likely has the smallest attack surface of them all, right ?
The problem here is as the other poster said. Tailscale is a security tool and yet the guys at Tailscale seem to be insistent on dumping everything INCLUDING the kitchen sink into it as a "feature".
That sort of attitude is not going to end well. You end up with a large bloated code base, which equals large attack surface.
Re: Tailscale didn't stop the Hugging Face intrusion
#60Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.
We also saw Anthropic post about “our agent escaped too” and while I understand the incident caused them to review, they found something and needed to disclose, the whole thing came across much worse and largely they got mocked or accused of trying to piggyback, so obviously there are good and bad ways.
If there are other providers with interesting takes, I think they would be worth hearing.