Live data from Hacker News

TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

tailscale.com

121–130 of 157 posts

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#121

Earlier quoted context omitted.

> we don't trust Tailscale. Just look at the thousands of unresolved Github issues, many of which are actually quite important/useful but have been ignored for months and years. This is a poor measure of quality. I've spent considerable time knee-deep in these issues in particular and the vast, vast majority of them are feature requests, bug reports awaiting more information from the submitter, or bug reports that ca…

> I absolutely guarantee they undergo regular formal security audits. There's no question. Well, they clearly don't if they have an "insecure argument handling" vulnerability. As others here have said already here, its an "venerable and ancient class of bugs". Its the sort of thing that should be picked up by modern defensive programming that includes fuzz testing. And it is CERTAINLY the sort of thing that should be…

Have you tried asking them for a copy of such a report? Or is your plan to just continue complaining until they make one public?

The finding in TFA was the result of a security audit.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#122

At $work we use Tailscale mostly because we were running into too many random issues with NAT with our standard DIY Wireguard setup, especially when people were working from hotels and other places with half-ass network setups. But we don't trust Tailscale. Just look at the thousands of unresolved Github issues, many of which are actually quite important/useful but have been ignored for months and years. We very much…

> And we only use Tailscale as a glorified VPN, we don't use their hundreds of extra random features like this SSH one.

Same, you are not alone. The Tailscale VPN stuff just works. None of their competitors can claim this that I'm aware of. We tried several other products and none of them were as reliable and 'just worked'. I imagine they spend a lot of time just keeping that stuff working.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#123

Earlier quoted context omitted.

> I absolutely guarantee they undergo regular formal security audits. There's no question. Well, they clearly don't if they have an "insecure argument handling" vulnerability. As others here have said already here, its an "venerable and ancient class of bugs". Its the sort of thing that should be picked up by modern defensive programming that includes fuzz testing. And it is CERTAINLY the sort of thing that should be…

Have you tried asking them for a copy of such a report? Or is your plan to just continue complaining until they make one public? The finding in TFA was the result of a security audit.

> The finding in TFA was the result of a security audit.

Don't you fucking dare.

Might I point you to the words "We would like to thank Anthropic and Ada Logics for reporting this issue.".

It was not commissioned by Tailscale. It was DONE BY OTHERS AND REPORTED TO TAILSCALE. Just like the fucking disclosure tells you.

Tailscale should not be relying on the random goodwill of others to do random audits of unknown coverage at random intervals.

That is not a serious approach to security.

They should be commissioning their own, paid out of their own pocket, at regular intervals, and publishing the results.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#124

Earlier quoted context omitted.

Did you try Headscale? https://github.com/juanfont/headscale or netbird? The latter has been great for me.

> Did you try Headscale? https://github.com/juanfont/headscale or netbird? Am aware of them but IIRC they are both unaudited which kind of brings us back to square one ? We would still end up running them at arms-length as we do with Tailscale at the moment. Isn't Headscale server-side only ? Also a bit strange that "Tailscale vs Netbird" doesn't feature more prominently on their "Compare Netbird" page. It is hidden…

(not top poster)

> Isn't Headscale server-side only ?

Yes. You're still running the native Tailscale client code on the hosts, which this evidence reveals can't be as trusted as Tailscale would like us to believe.

I also wouldn't trust Headscale fully. It had a critical defect at some point that, IIRC, would allow an attacker to rotate the key of a registered node without auth to a value chosen by the attacker. And its primary maintainer is a member of the Tailscale team, apparently maintained with full approval of their employer and with reasonable transparency between the projects, but nonetheless the overlap is a little close for comfort.

Frankly, as you've said, I don't trust any of these solutions to be anything more than a convenient way to jump onto a bastion or another host of minimal consequence to get into the network and jump onwards.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#125
post #122

At $work we use Tailscale mostly because we were running into too many random issues with NAT with our standard DIY Wireguard setup, especially when people were working from hotels and other places with half-ass network setups. But we don't trust Tailscale. Just look at the thousands of unresolved Github issues, many of which are actually quite important/useful but have been ignored for months and years. We very much…

> And we only use Tailscale as a glorified VPN, we don't use their hundreds of extra random features like this SSH one. Same, you are not alone. The Tailscale VPN stuff just works. None of their competitors can claim this that I'm aware of. We tried several other products and none of them were as reliable and 'just worked'. I imagine they spend a lot of time just keeping that stuff working.

I haven't had problems with NetBird on Android and Linux. I have also used tailscale and found it comparable.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#127

At $work we use Tailscale mostly because we were running into too many random issues with NAT with our standard DIY Wireguard setup, especially when people were working from hotels and other places with half-ass network setups. But we don't trust Tailscale. Just look at the thousands of unresolved Github issues, many of which are actually quite important/useful but have been ignored for months and years. We very much…

I've been planning a similarly "paranoid" (but apparently not that paranoid) Tailscale setup, for the same reasons. Another concern I have is whether a compromise of Tailscale's own infra could let an attacker just add itself to my network. Apparently the "Tailnet Lock" feature mitigates this, but it is off by default . If I was an APT, compromising Tailscale would be priority number 1!

> If I was an APT, compromising Tailscale would be priority number 1!

Crowdstrike would be at a much higher priority. They already have a cloud connected root console to all the machines in entire corporations. Compromising your network is small potatoes compared to that.

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#128

Earlier quoted context omitted.

> we don't trust Tailscale. Just look at the thousands of unresolved Github issues, many of which are actually quite important/useful but have been ignored for months and years. This is a poor measure of quality. I've spent considerable time knee-deep in these issues in particular and the vast, vast majority of them are feature requests, bug reports awaiting more information from the submitter, or bug reports that ca…

> I absolutely guarantee they undergo regular formal security audits. There's no question. Well, they clearly don't if they have an "insecure argument handling" vulnerability. As others here have said already here, its an "venerable and ancient class of bugs". Its the sort of thing that should be picked up by modern defensive programming that includes fuzz testing. And it is CERTAINLY the sort of thing that should be…

[deleted]

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#129
post #24

I'll stick to my 100% self-hosted Wireguard setup, thank you very much.

haha self hosted wireguard, an opportunity to find out AllowedIPs: 0.0.0.0/0 does the opposite of what you think it will do

Is this what your referring to? https://utcc.utoronto.ca/~cks/space/blog/linux/WireGuardAllo...

Re: TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

#130

Earlier quoted context omitted.

> I absolutely guarantee they undergo regular formal security audits. There's no question. Well, they clearly don't if they have an "insecure argument handling" vulnerability. As others here have said already here, its an "venerable and ancient class of bugs". Its the sort of thing that should be picked up by modern defensive programming that includes fuzz testing. And it is CERTAINLY the sort of thing that should be…

Have you tried asking them for a copy of such a report? Or is your plan to just continue complaining until they make one public? The finding in TFA was the result of a security audit.

As an open source maintainer of a fairly large project, we get reports from Ada Logics and similar firms every once in a while and those are absolutely not the same as a proper security audit (which we've also had commissioned in the past). Reports are just a description of a particular issue, not the deeper analysis of the general structure of the codebase that you get from a good audit.
Post reply on HN