Live data from Hacker News

Tailscale didn't stop the Hugging Face intrusion

tailscale.com

151–160 of 239 posts

Re: Tailscale didn't stop the Hugging Face intrusion

#152

Earlier quoted context omitted.

I mean, they do happily explain the TailScale features that you can use to avoid this kind of issue, but the general advice of "don't leave long-lived keys lying around where they're accessible, do anything except for that" is pretty generic, good advice.

You always need a long-lived key somewhere. Keeping it in an HSM is probably the safest, but also pretty expensive.

Suppose someone could break RSA / Elliptic Curve Crypto, mathematically (because the hardness assumptions were flawed).

This person doesn't need to store the private keys, and has the luxury to recompute them on the fly when needed!

Re: Tailscale didn't stop the Hugging Face intrusion

#153

Earlier quoted context omitted.

Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.

For me, the calculus is simply: “there’s no way I could do this better than Tailscale”.

That's true, but for some things I require a bar much higher than "at least as good as I could do."

Re: Tailscale didn't stop the Hugging Face intrusion

#154

Earlier quoted context omitted.

I think this is simply a case of Tailscale saying, we've got no idea what these guys (OpenAI) are talking about. All these incidents are scarce on technical details . Honestly, IMHO, OpenAI and Anthropic are now actively pushing for AI regulation, as a defence mechanism. These are false flag operations.

Tailwind or Tailscale? I think the case is Tailscale is saying, "It's technically not our fault, but we still should've stopped it."

Freudian slip? Tailscale, corrected. Thank you, it's been a long day.

Re: Tailscale didn't stop the Hugging Face intrusion

#155

Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.

if your article is about how your product was insufficient to protect against something, you get a pass i guess

Re: Tailscale didn't stop the Hugging Face intrusion

#156

I love you Tailscale but please we don't need a 2k words ai written essay when the actual substance can fit in 3 sentences. That's not good for anyone.

As someone who's not a security professional I actually found it both interesting and informative. Experts usually are not the target audience for content marketing after all.

Re: Tailscale didn't stop the Hugging Face intrusion

#157

Earlier quoted context omitted.

I think this is simply a case of Tailscale saying, we've got no idea what these guys (OpenAI) are talking about. All these incidents are scarce on technical details . Honestly, IMHO, OpenAI and Anthropic are now actively pushing for AI regulation, as a defence mechanism. These are false flag operations.

> These are false flag operations. The level of "I need to be the smartest person in the room" bullheaded skepticism on Hacker News has always been bad, but now with these latest LLM developments it is just completely out of control. A company is reporting an intrusion and how they plan to address the vulnerabilities it exposed in the future, and you're here going "seems shopped, I can tell from the pixels".

I don't think that's what is being said. False flag, I presume in this scenario is to say were going to do something about the impending "AI threat" and to be associated with it. There is probably little threat, but to some investors this starts to look like perceived "AGI". Getting your name involved in the hype is marketing 101

Re: Tailscale didn't stop the Hugging Face intrusion

#158

Earlier quoted context omitted.

I think this is simply a case of Tailscale saying, we've got no idea what these guys (OpenAI) are talking about. All these incidents are scarce on technical details . Honestly, IMHO, OpenAI and Anthropic are now actively pushing for AI regulation, as a defence mechanism. These are false flag operations.

> These are false flag operations. The level of "I need to be the smartest person in the room" bullheaded skepticism on Hacker News has always been bad, but now with these latest LLM developments it is just completely out of control. A company is reporting an intrusion and how they plan to address the vulnerabilities it exposed in the future, and you're here going "seems shopped, I can tell from the pixels".

Maybe because I can spot the pixels, I can possibly see in 8K?

Re: Tailscale didn't stop the Hugging Face intrusion

#159
post #145

Another driving home of the point that LLMs can be so damn FAST. I finally got around to moving a homeserver project from one machine to another last weekend. 4 docker containers and a couple postgres DBs. A year ago, I would have been happy with a couple hours of downtime while I dumped databases, rsynced data directories, hand-wrote new compose files, etc. This time, I pointed an agent at both servers and the downt…

Agent racing sounds fun, where each agent is given a suite of increasingly hard but verifiable tasks, and the agent that completes them all correctly first, wins. You can even have "speed classes" where token generation speed is limited. Or you could even set up categories like yacht racing.

Likewise you could have token golf, instead of going for wall clock time it's going for minimum token count.

Re: Tailscale didn't stop the Hugging Face intrusion

#160

Wow, this article is super smart marketing by tailscale. Not only do they list all the nice and expensive features, that can help in such a situation but they also show that someone at huggingface made a very stupid thing by writing a reusable auth key in an env file. Everyone using mesh VPNs like tailscale, netbird etc. knows that this is like leaving the keys right at the door.

And yet everyone seems to do it anyway. Fine for medium security, but maybe the product needs a high security mode that enforces inconvenient decisions?

[deleted]
Post reply on HN