> One of those 136 credentials was a reusable Tailscale auth key, used to create new Tailscale CI (continuous integration, used for automated testing) nodes in their tailnet. The agent copied that key into a series of external sandboxes and used it, over several days, to enroll a total of 181 nodes into Hugging Face’s tailnet. Those nodes each received a Tailscale identity tag granting all the access a CI node would…
Tailscale didn't stop the Hugging Face intrusion
131–140 of 239 posts
Re: Tailscale didn't stop the Hugging Face intrusion
#132Earlier quoted context omitted.
If you want a hard-to-use VPN with minimal features and minimal surface area, as you said, Wireguard is right there. Tailscale is convenient Wireguard.
I use Wireguard for several site-to-site VPNs. It just works. I never have to worry about it, and there are very few configuration settings to mess up (unlike, say, IPsec, which is a nightmare.)
Re: Tailscale didn't stop the Hugging Face intrusion
#133Re: Tailscale didn't stop the Hugging Face intrusion
#134Re: Tailscale didn't stop the Hugging Face intrusion
#135Earlier quoted context omitted.
It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity. I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it. Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
The large attack surface is a good point. I started using it initially and the ease of setting up a vpn was nice, but then I came across few security vulnerability postings which led to concern so I went to Wireguard. I think they should reign in the features and treat it as a secure vpn first and foremost and remove unnecessary features to minimize the attack surface.
If you layer and segment correctly you can build atop a secure core and have some decent security.
Re: Tailscale didn't stop the Hugging Face intrusion
#136Earlier quoted context omitted.
And I have no problem with this. Infact it would be nice to be a point of pride to be there to say how your security is handled.
I think this is simply a case of Tailscale saying, we've got no idea what these guys (OpenAI) are talking about. All these incidents are scarce on technical details . Honestly, IMHO, OpenAI and Anthropic are now actively pushing for AI regulation, as a defence mechanism. These are false flag operations.
I think the case is Tailscale is saying, "It's technically not our fault, but we still should've stopped it."
Re: Tailscale didn't stop the Hugging Face intrusion
#137[flagged]
Bot account. This sounded like LLM text. I went through all your other comments, and of your thousands of comments written in 35 days, every other one is also similarly written by LLM. Some superficial comment usually commenting on the title, always lowercase, always load-bearing and honest.
Re: Tailscale didn't stop the Hugging Face intrusion
#138> No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously. im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
Re: Tailscale didn't stop the Hugging Face intrusion
#139Re: Tailscale didn't stop the Hugging Face intrusion
#140Earlier quoted context omitted.
Bot account. This sounded like LLM text. I went through all your other comments, and of your thousands of comments written in 35 days, every other one is also similarly written by LLM. Some superficial comment usually commenting on the title, always lowercase, always load-bearing and honest.
Sure seems like it. Real humans don't write exclusively one sentence comments. It doesn't look like the post history of anyone here that I'm fairly sure is a real meat based mammal. It looks like someone gave an LLM an instruction to write exclusively short and snappy comments that are somewhat relevant to the original post.
> … comments that are somewhat relevant to the original post.
This is a really common tell for HN bot accounts I find, even when effectively disguised/customized to drop the most obvious LLM cliches/em-dashes/etc.In a vacuum a specific comment may be more or less fine, or just a tad over baked like the parent post giving it an uncanny valley feel though otherwise passable.
But even people who diligently try to stay on topic on a forum like HN will occasionally use a post as a segue or jumping off point to some other idea, tangentially related news, personal experience, or random thought that pops into their head if it feels like it (kinda) “fits”.
After scrolling through a few dozen replies in an account’s history that are all directly related to the post topic it no longer looks human in aggregate.
I’m sure the spammers will try to incorporate that idiosyncrasy into their prompts eventually but not sure it will help more than hurt.