Earlier quoted context omitted.
(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins. Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin.
But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ? Those are an ancient class of bugs that should be picked up by any competent security review.
Tailscale didn't stop the Hugging Face intrusion
71–80 of 239 posts
Re: Tailscale didn't stop the Hugging Face intrusion
#72Now everyone is trying to bandwagon onto it, first OpenAI, and now tailscale?
Re: Tailscale didn't stop the Hugging Face intrusion
#73Re: Tailscale didn't stop the Hugging Face intrusion
#74Re: Tailscale didn't stop the Hugging Face intrusion
#75Re: Tailscale didn't stop the Hugging Face intrusion
#76Earlier quoted context omitted.
> How would it be different with plain wireguard? Seriously ? You do realise that of all the security tools on the planet, plain wireguard most likely has the smallest attack surface of them all, right ? The problem here is as the other poster said. Tailscale is a security tool and yet the guys at Tailscale seem to be insistent on dumping everything INCLUDING the kitchen sink into it as a "feature". That sort of atti…
I am talking especially about the LLM part. Also a kinder tone in your comments would be more appreciated.
Re: Tailscale didn't stop the Hugging Face intrusion
#77Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.
Re: Tailscale didn't stop the Hugging Face intrusion
#78Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.
Re: Tailscale didn't stop the Hugging Face intrusion
#79Earlier quoted context omitted.
[flagged]
(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you pe…