Earlier quoted context omitted.
> we don't trust Tailscale. Just look at the thousands of unresolved Github issues, many of which are actually quite important/useful but have been ignored for months and years. This is a poor measure of quality. I've spent considerable time knee-deep in these issues in particular and the vast, vast majority of them are feature requests, bug reports awaiting more information from the submitter, or bug reports that ca…
> I absolutely guarantee they undergo regular formal security audits. There's no question. Well, they clearly don't if they have an "insecure argument handling" vulnerability. As others here have said already here, its an "venerable and ancient class of bugs". Its the sort of thing that should be picked up by modern defensive programming that includes fuzz testing. And it is CERTAINLY the sort of thing that should be…
The finding in TFA was the result of a security audit.