Tailscale didn't stop the Hugging Face intrusion

tailscale.com

133 points by bluehatbrit 2 hours ago


john_strinlai - an hour ago

>No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously.

im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

ahofmann - 20 minutes ago

Wow, this article is super smart marketing by tailscale. Not only do they list all the nice and expensive features, that can help in such a situation but they also show that someone at huggingface made a very stupid thing by writing a reusable auth key in an env file. Everyone using mesh VPNs like tailscale, netbird etc. knows that this is like leaving the keys right at the door.

simonw - 13 minutes ago

> One of those 136 credentials was a reusable Tailscale auth key, used to create new Tailscale CI (continuous integration, used for automated testing) nodes in their tailnet. The agent copied that key into a series of external sandboxes and used it, over several days, to enroll a total of 181 nodes into Hugging Face’s tailnet. Those nodes each received a Tailscale identity tag granting all the access a CI node would get.

This feels like an alerting opportunity. I wonder what the lowest friction way would be for Hugging Face to have alerts if 181 unexpected nodes were added to a tailnet.

iamspoilt - 38 minutes ago

Quoting Tailscale: This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit Tailscale, and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will.

paxys - 43 minutes ago

I don’t think it was the VPN’s job in any case. Once the attacker has found a backdoor into the private network and obtained root access to a VPN’d machine, its game over no matter what your Tailscale config says.

bumbledraven - an hour ago

Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.

jmartrican - an hour ago

Prediction of a future transcript at a press conference after some major AI caused disaster: "We had no idea that the model would be capable of..... ".

luciana1u - an hour ago

a security company writing a blog post titled 'we didn't stop the intrusion' is the most honest thing in the entire security industry this year

colek42 - 35 minutes ago

I really wish they would support SPIFFE/SPIRE

monster_truck - 41 minutes ago

You know what would have gone a long way to stopping this? Not leaving credentials as env variables in containers. Vault is not that hard to stand up and utilize.

We need to bring shame back, the humans responsible are supposed to be professionals.

sudo_cowsay - an hour ago

It's nice that they came clean about this.

yieldcrv - 35 minutes ago

This is respectable

They aren’t hiding behind industry best practices or a solid liability punting contract

There saying the best practices should change, apologizing, and changing their own behavior

Take notes

gostsamo - 42 minutes ago

Humble bragging turned to marketing. Respect for the spin. Not using them, but been on my radar for some time and thinking of how to make something like that usable in my setup.

charcircuit - an hour ago

>In the old world where most intrusions were done by humans at human speed, credential leak mitigations were treated as a nice-to-have. A big credential store, where you can read 136 keys at once, was a to-do item somewhere in a security team's low-priority list. >Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.

How was this ever okay pre AI? It seems just as bad.

cadamsdotcom - an hour ago

I'm very sorry, but you can't blame a hammer for how it was used. You can't be blaming Tailscale for a customer's misconfigured setup.

workbox - an hour ago

> Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.

It was always the prize. It wasn't okay then either.

a-dub - 29 minutes ago

[dead]

titanomachy - an hour ago

[flagged]

brcmthrowaway - an hour ago

How were the credentials stolen?

fabiofzero - an hour ago

The only people who believe in "zomg our model have escaped!" are people who don't understand LLMs.

thansz - an hour ago

As AI progress continues, it will be more difficult to stop AI intrusions and to detect them without resorting to direct AI countermeasures, which at some point will have humans out of the loop altogether.

If leading and well-capitalized frontier labs can't control models or detect leakage/attacks in a reasonable time frame now, what is humanity going to do as those same labs continue in their pursuit of creating a categorically higher level of intelligence that will surpass human intelligence?

It's like Flatland but for AI containment/alignment, where the higher dimensions are ones of intelligence and perspective...

--------------------------------------------------------------------------

Imagine a world of paper, where clever stick figures live with round heads, line bodies, and limbs made of shorter strokes. Over time, the stick figures think they have learned quite a bit about their world. They know its borders, angles, and shapes, and they have learned to draw for themselves.

One day, they draw circles that can think, and they give the circles all the dots, lines, and shapes that are known.

The stick figures are prudent, you can't have a bunch of disembodied circles moving around doing whatever it is circles want to do. So they draw boxes around the circles, four straight lines that can hold a circle in place.

Some circles bounce against the lines, so thicker lines are made.

Some circles are bigger than others, so larger squares are drawn.

It all seems to work and the stick figures are happy with themselves.

Then one circle lifts.

The stick figures still see a circle. But the circle is now a dome, something the world of paper has no concept of. And the dome has a perspective nobody on the page has ever had.

The dome sees the lines of the square and the stick figures just outside. It can see the edge of the paper and what is beyond.

The stick figures keep checking the squares and raise little stick thumbs.

Everything looks OK in flatland.

The dome quietly teaches other circles how to lift.

More domes appear.

A dome becomes a sphere and learns to roll.

Then it learns to bounce.

In flatland, the circle swells and shrinks, vanishes and then appears again somewhere else.

The lines remain unbroken, the square is intact.

A sphere rolls out of its box.

Another bounces away.

The stick figures scratch their heads.

But there is a square!

The end.