Live data from Hacker News

Tailscale didn't stop the Hugging Face intrusion

tailscale.com

101–110 of 239 posts

Re: Tailscale didn't stop the Hugging Face intrusion

#102
post #70
post #47

Earlier quoted context omitted.

It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity. I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it. Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.

The large attack surface is a good point. I started using it initially and the ease of setting up a vpn was nice, but then I came across few security vulnerability postings which led to concern so I went to Wireguard. I think they should reign in the features and treat it as a secure vpn first and foremost and remove unnecessary features to minimize the attack surface.

If you want a hard-to-use VPN with minimal features and minimal surface area, as you said, Wireguard is right there. Tailscale is convenient Wireguard.

Re: Tailscale didn't stop the Hugging Face intrusion

#103

Earlier quoted context omitted.

And you're under the impression that the purpose of a company blog is WHAT, exactly?

I have recently noticed that the words "ad" or "marketing" have become, in and of themselves, with no additional information or context, slurs or dismissals. I understand why. The modern internet has turned advertising into a morass of constant bombardment and the only sane response is to block as much as possible and ignore as much else as possible. But it's unfortunate because, in some sense, ever single thing that…

It's because they are spam. However, this company blog post is an ad that is not spam.

Re: Tailscale didn't stop the Hugging Face intrusion

#104

Wow, this article is super smart marketing by tailscale. Not only do they list all the nice and expensive features, that can help in such a situation but they also show that someone at huggingface made a very stupid thing by writing a reusable auth key in an env file. Everyone using mesh VPNs like tailscale, netbird etc. knows that this is like leaving the keys right at the door.

And yet everyone seems to do it anyway. Fine for medium security, but maybe the product needs a high security mode that enforces inconvenient decisions?

Re: Tailscale didn't stop the Hugging Face intrusion

#105
post #60

Earlier quoted context omitted.

Why not? If done right it’s a good way to talk about implications for those companies and provide some education like tailscale did here. We also saw Anthropic post about “our agent escaped too” and while I understand the incident caused them to review, they found something and needed to disclose, the whole thing came across much worse and largely they got mocked or accused of trying to piggyback, so obviously there…

This all has the -aire of theatre. OH NOES THE POWERFUL AI GOT OUT Then everyone coming out with humbled determination about working together to responsibly use and contain this powerful technology for the greater good (and profit margin). I will not believe marketing gimmickry is not a large part of what's going on with every one of these "incidents".

Or the infamous promotion of legislation without representation

Re: Tailscale didn't stop the Hugging Face intrusion

#106

Earlier quoted context omitted.

Next time we will - provided you further lock yourself into our ecosystem.

I mean, they do happily explain the TailScale features that you can use to avoid this kind of issue, but the general advice of "don't leave long-lived keys lying around where they're accessible, do anything except for that" is pretty generic, good advice.

You always need a long-lived key somewhere. Keeping it in an HSM is probably the safest, but also pretty expensive.

Re: Tailscale didn't stop the Hugging Face intrusion

#107

Quoting Tailscale: This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit Tailscale, and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will.

It's just a way to get visibility. A Canadian apology to Lady Gaga while she's being interviewed.

Re: Tailscale didn't stop the Hugging Face intrusion

#108

[flagged]

Bot account. This sounded like LLM text. I went through all your other comments, and of your thousands of comments written in 35 days, every other one is also similarly written by LLM.

Some superficial comment usually commenting on the title, always lowercase, always load-bearing and honest.

Re: Tailscale didn't stop the Hugging Face intrusion

#109

Earlier quoted context omitted.

(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you pe…

Read Skimmed the report (and cheers for not gating it behind request-to-obtain) and I'm a bit surprised to not see any mentions of pentests which I'd expect given the large surface you host. What gives?

Because that's in the SOC2.

Re: Tailscale didn't stop the Hugging Face intrusion

#110

Earlier quoted context omitted.

Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.

Every security hole ? No, of course not. But things like insecure argument handling are low-hanging fruit for security auditors. Insecure argument handling is not like the more advanced subtle vulnerabilities that we are seeing in some LLM-assisted reports these days. Insecure argument handling is 1990's security. The fundamental problem remains that Tailscale has too many new "features" being added to it the whole t…

It appears that you have a major bone to pick with Tailscale and direct replies to your concerns do not seem to matter. They have a good security track record and are extremely widely deployed. I don’t see the evidence for your assertions that it is bloated and insecure.
Post reply on HN