Live data from Hacker News

Tailscale didn't stop the Hugging Face intrusion

tailscale.com

61–70 of 239 posts

Re: Tailscale didn't stop the Hugging Face intrusion

#61

Earlier quoted context omitted.

[flagged]

(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you pe…

The majority of your security bulletins are as the result of third-party reports to you.

Which, by definition, means they are not done by you, which means you don't know when they will be done or how much of your code base they are looking at.

I think you know full well what I mean by a security audit. If you don't, go look at, for example, the ones that Mullvad publish for their software https://mullvad.net/en/blog/tag/audits.

Please do not try to portray SOC2 as being the same thing as a code audit.

And IF you have regular code audits, then please publish suitably redacted reports in public on your website. Just like everyone else does !

Re: Tailscale didn't stop the Hugging Face intrusion

#62
post #54

Earlier quoted context omitted.

> I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it Doesn't this apply to any application you use? How would it be different with plain wireguard?

> How would it be different with plain wireguard? Seriously ? You do realise that of all the security tools on the planet, plain wireguard most likely has the smallest attack surface of them all, right ? The problem here is as the other poster said. Tailscale is a security tool and yet the guys at Tailscale seem to be insistent on dumping everything INCLUDING the kitchen sink into it as a "feature". That sort of atti…

I am talking especially about the LLM part.

Also a kinder tone in your comments would be more appreciated.

Re: Tailscale didn't stop the Hugging Face intrusion

#64

Earlier quoted context omitted.

[flagged]

(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you pe…

That link is a list of incidents while the parent comment is referring to security audits of the code.

Re: Tailscale didn't stop the Hugging Face intrusion

#65

Earlier quoted context omitted.

(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you pe…

The majority of your security bulletins are as the result of third-party reports to you. Which, by definition, means they are not done by you, which means you don't know when they will be done or how much of your code base they are looking at. I think you know full well what I mean by a security audit. If you don't, go look at, for example, the ones that Mullvad publish for their software https://mullvad.net/en/blog/…

(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins.

Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin.

Re: Tailscale didn't stop the Hugging Face intrusion

#66

Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.

I lead the customer engineering org at Tailscale. We think this is a great idea and we're discussing internally potentially adding that to the console. In the meantime, if you'd like to get an assessment, please feel free to open a support ticket ( https://tailscale.com/contact/support?type=other&subject=sec... ) and we'll happily take a look

Random idea: When a recommendation is not being followed for a customer because of some deliberate or idiosyncratic reason, a notes field could:

1. Help them remember why, so that they aren't confused the next time they re-run the checkup. ("Oh yeah, we wanted to do X but we can't until we retire Y because it's not compatible.")

2. If it's clearly labeled as info also shared with Tailscale, product managers could use it to help generate theories about why certain customers don't do X.

Re: Tailscale didn't stop the Hugging Face intrusion

#68

Earlier quoted context omitted.

The majority of your security bulletins are as the result of third-party reports to you. Which, by definition, means they are not done by you, which means you don't know when they will be done or how much of your code base they are looking at. I think you know full well what I mean by a security audit. If you don't, go look at, for example, the ones that Mullvad publish for their software https://mullvad.net/en/blog/…

(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins. Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin.

But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ?

Those are an ancient class of bugs that should be picked up by any competent security review.

Re: Tailscale didn't stop the Hugging Face intrusion

#69
Honestly, at this point if Tailscale is "guilty" then what about the ISP? And the electricity company?

And by saying that, I am not saying that they absolutely couldn't do anything about the stolen credentials, but still, they don't seem to really be the issue in the story.

It just seems like a PR post and it makes their solution at the same time looks good for taking accountability (if we don't wonder "accountability on what?") but at the same time they appear as security failing, which they aren't. That's very odd to me.

Re: Tailscale didn't stop the Hugging Face intrusion

#70
post #47

Earlier quoted context omitted.

[flagged]

It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity. I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it. Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.

The large attack surface is a good point. I started using it initially and the ease of setting up a vpn was nice, but then I came across few security vulnerability postings which led to concern so I went to Wireguard. I think they should reign in the features and treat it as a secure vpn first and foremost and remove unnecessary features to minimize the attack surface.
Post reply on HN