> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.
Tailscale didn't stop the Hugging Face intrusion
111–120 of 239 posts
Re: Tailscale didn't stop the Hugging Face intrusion
#112Earlier quoted context omitted.
Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.
[flagged]
Re: Tailscale didn't stop the Hugging Face intrusion
#113Earlier quoted context omitted.
The person I'm replying to says they deserve "a lot of respect for this"
i said i have a lot of respect for this. whether you do or not is up to you. anything a company writes is an advertisement by the nature of being written by a company. i dont think that means anything a company writes is bad by default. there are many corporate blogs i enjoy reading, or learn from, etc., despite the fact that they are all technically advertisements. in this case, tailscale is setting a higher expecta…
What exactly is the higher expectation? As someone with little expertise and no stake in any of this, the blog reads as "our products are great and could have solved this problem if they were being used correctly, so it's not our fault" with a few vague proclamations about how they will improve their UX. This isn't at all a bad thing, it just isn't very notable in my opinion.
Re: Tailscale didn't stop the Hugging Face intrusion
#114Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.
Re: Tailscale didn't stop the Hugging Face intrusion
#115Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.
Re: Tailscale didn't stop the Hugging Face intrusion
#116I would say HuggingFace needs to prioritize both security metrics/alerts and metrics/alerts for node count. And not leave long-lived keys accessible easily like this.
It would have been way more groundbreaking if the agent found an actual vulnerability in Tailscale.
Re: Tailscale didn't stop the Hugging Face intrusion
#117[flagged]
Bot account. This sounded like LLM text. I went through all your other comments, and of your thousands of comments written in 35 days, every other one is also similarly written by LLM. Some superficial comment usually commenting on the title, always lowercase, always load-bearing and honest.
Re: Tailscale didn't stop the Hugging Face intrusion
#118Earlier quoted context omitted.
i said i have a lot of respect for this. whether you do or not is up to you. anything a company writes is an advertisement by the nature of being written by a company. i dont think that means anything a company writes is bad by default. there are many corporate blogs i enjoy reading, or learn from, etc., despite the fact that they are all technically advertisements. in this case, tailscale is setting a higher expecta…
> tailscale is setting a higher expectation for themselves What exactly is the higher expectation? As someone with little expertise and no stake in any of this, the blog reads as "our products are great and could have solved this problem if they were being used correctly, so it's not our fault" with a few vague proclamations about how they will improve their UX. This isn't at all a bad thing, it just isn't very notab…
better defaults, better documentation, better UX, and "But, we didn't stop it. Next time, we will." are all commitments that they didn't need to make, but now they need to follow through with or lose face.
>it just isn't very notable in my opinion.
i agree that this seems to be getting way more attention than i would have expected.
Re: Tailscale didn't stop the Hugging Face intrusion
#119Re: Tailscale didn't stop the Hugging Face intrusion
#120That's an option designed for users who are concerned about sending telemetry metadata to Tailscale.”
And imho a serious security architect should never ever allow telemetry on security products. Far too many risks.