Live data from Hacker News

Tailscale didn't stop the Hugging Face intrusion

tailscale.com

111–120 of 239 posts

Re: Tailscale didn't stop the Hugging Face intrusion

#111

> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

Tailscale is responsible for designing a system whose convenient defaults allowed a stolen credential to have a very large blast radius. A marketing blog is not changing that.

Re: Tailscale didn't stop the Hugging Face intrusion

#112
post #99

Earlier quoted context omitted.

Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.

[flagged]

i think its probably okay to drop it when you are this far deep into a conversation and the affiliation has already been stated multiple times in the existing comment chain.

Re: Tailscale didn't stop the Hugging Face intrusion

#113

Earlier quoted context omitted.

The person I'm replying to says they deserve "a lot of respect for this"

i said i have a lot of respect for this. whether you do or not is up to you. anything a company writes is an advertisement by the nature of being written by a company. i dont think that means anything a company writes is bad by default. there are many corporate blogs i enjoy reading, or learn from, etc., despite the fact that they are all technically advertisements. in this case, tailscale is setting a higher expecta…

> tailscale is setting a higher expectation for themselves

What exactly is the higher expectation? As someone with little expertise and no stake in any of this, the blog reads as "our products are great and could have solved this problem if they were being used correctly, so it's not our fault" with a few vague proclamations about how they will improve their UX. This isn't at all a bad thing, it just isn't very notable in my opinion.

Re: Tailscale didn't stop the Hugging Face intrusion

#115

Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.

This is the kind of ad that may be opportunistic but sort of speaks for itself: they're not going to make excuses. I've been happy with Tailscale for years and this is part of why.

Re: Tailscale didn't stop the Hugging Face intrusion

#116
This actually shows that it was a human error on HuggingFace's end that led to that "breach".

I would say HuggingFace needs to prioritize both security metrics/alerts and metrics/alerts for node count. And not leave long-lived keys accessible easily like this.

It would have been way more groundbreaking if the agent found an actual vulnerability in Tailscale.

Re: Tailscale didn't stop the Hugging Face intrusion

#117
post #108

[flagged]

Bot account. This sounded like LLM text. I went through all your other comments, and of your thousands of comments written in 35 days, every other one is also similarly written by LLM. Some superficial comment usually commenting on the title, always lowercase, always load-bearing and honest.

Sure seems like it. Real humans don't write exclusively one sentence comments. It doesn't look like the post history of anyone here that I'm fairly sure is a real meat based mammal. It looks like someone gave an LLM an instruction to write exclusively short and snappy comments that are somewhat relevant to the original post.

Re: Tailscale didn't stop the Hugging Face intrusion

#118

Earlier quoted context omitted.

i said i have a lot of respect for this. whether you do or not is up to you. anything a company writes is an advertisement by the nature of being written by a company. i dont think that means anything a company writes is bad by default. there are many corporate blogs i enjoy reading, or learn from, etc., despite the fact that they are all technically advertisements. in this case, tailscale is setting a higher expecta…

> tailscale is setting a higher expectation for themselves What exactly is the higher expectation? As someone with little expertise and no stake in any of this, the blog reads as "our products are great and could have solved this problem if they were being used correctly, so it's not our fault" with a few vague proclamations about how they will improve their UX. This isn't at all a bad thing, it just isn't very notab…

>What exactly is the higher expectation?

better defaults, better documentation, better UX, and "But, we didn't stop it. Next time, we will." are all commitments that they didn't need to make, but now they need to follow through with or lose face.

>it just isn't very notable in my opinion.

i agree that this seems to be getting way more attention than i would have expected.

Re: Tailscale didn't stop the Hugging Face intrusion

#119
post #99

Earlier quoted context omitted.

Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.

[flagged]

Try to be civil

Re: Tailscale didn't stop the Hugging Face intrusion

#120
“ the agent ran Tailscale with --no-logs-no-support, which suppresses reporting from that client.

That's an option designed for users who are concerned about sending telemetry metadata to Tailscale.”

And imho a serious security architect should never ever allow telemetry on security products. Far too many risks.

Post reply on HN