Live data from Hacker News

Tailscale didn't stop the Hugging Face intrusion

tailscale.com

71–80 of 239 posts

Re: Tailscale didn't stop the Hugging Face intrusion

#71

Earlier quoted context omitted.

(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins. Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin.

But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ? Those are an ancient class of bugs that should be picked up by any competent security review.

Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.

Re: Tailscale didn't stop the Hugging Face intrusion

#75
sorry I know off topic, is there any alternative VPN to tailscale. actually I have open Web socket to my mobile from my PC to stream screen record using ffmpeg. it's my own app . so anyway tailscale sometimes is slow . is there any alternative free service like tailscale vpn ? ( don't want to use anything like parsec etc , I want to use my own app)

Re: Tailscale didn't stop the Hugging Face intrusion

#76
post #62

Earlier quoted context omitted.

> How would it be different with plain wireguard? Seriously ? You do realise that of all the security tools on the planet, plain wireguard most likely has the smallest attack surface of them all, right ? The problem here is as the other poster said. Tailscale is a security tool and yet the guys at Tailscale seem to be insistent on dumping everything INCLUDING the kitchen sink into it as a "feature". That sort of atti…

I am talking especially about the LLM part. Also a kinder tone in your comments would be more appreciated.

[flagged]

Re: Tailscale didn't stop the Hugging Face intrusion

#78

Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.

And I have no problem with this. Infact it would be nice to be a point of pride to be there to say how your security is handled.

Re: Tailscale didn't stop the Hugging Face intrusion

#79

Earlier quoted context omitted.

[flagged]

(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you pe…

Read Skimmed the report (and cheers for not gating it behind request-to-obtain) and I'm a bit surprised to not see any mentions of pentests which I'd expect given the large surface you host. What gives?
Post reply on HN