Comment by john_strinlai
3 hours ago
>No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously.
im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.
Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.
This is the kind of ad that may be opportunistic but sort of speaks for itself: they're not going to make excuses. I've been happy with Tailscale for years and this is part of why.
And I have no problem with this. Infact it would be nice to be a point of pride to be there to say how your security is handled.
i doubt it. it's pretty risky to set higher expectations for yourself when no one was really asking.
they are a company, therefor anything they write is an advertisement of sorts, but that doesn't make it bad by default. cloudflare and netflix (among others) also write blog posts that i find interesting and enjoy reading, despite being ads at their core.
If they take actions that would have further prevented or limited this attack then it seems like a good form of advertising to me.
Why not? If done right it’s a good way to talk about implications for those companies and provide some education like tailscale did here.
We also saw Anthropic post about “our agent escaped too” and while I understand the incident caused them to review, they found something and needed to disclose, the whole thing came across much worse and largely they got mocked or accused of trying to piggyback, so obviously there are good and bad ways.
If there are other providers with interesting takes, I think they would be worth hearing.
This all has the -aire of theatre. OH NOES THE POWERFUL AI GOT OUT
Then everyone coming out with humbled determination about working together to responsibly use and contain this powerful technology for the greater good (and profit margin).
I will not believe marketing gimmickry is not a large part of what's going on with every one of these "incidents".
1 reply →
All aboard the public relations hype train! choo choo!
Oh no! An advertisement! Whatever shall we do‽
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
> I can "trust" that they know what they're doing
I wish I could say the same.
At $work we use Tailscale but only bare minimum and at arms length and only because we have to (people were having NAT issues with standard Wireguard).
None of their code has had a security audit, let alone regular ones. Yes they make a big song and dance about SOC2/ISO27001 but that is NOT the same thing, that's just shiny tick-boxes for compliance departments.
They seem to rely entirely on the random goodwill of others to do random audits of unknown coverage at random intervals, not exactly reassuring.
"Tailsale Lock" is, being polite, a hot mess. So many sharp edges and footguns.
Their introduction of TPM-by-default and then removing it a few weeks later because of a seemingly small number of edge-cases and very odd reasoning was just weird.
Yes they are nice guys to chat to and all that. But for a security tool they need to up their game seriously.
(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing."
It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews.
The security audit report, which you perhaps imagine to be a long list of vulnerabilities... doesn't look like that. It says we don't have a long list of vulnerabilities. The security bulletins are all here: https://tailscale.com/security-bulletins
12 replies →
It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity.
I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it.
Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network.
6 replies →
Tailscale is responsible for designing a system whose convenient defaults allowed a stolen credential to have a very large blast radius. A marketing blog is not changing that.
Glad to see companies owning responsibility and putting out a message without corporate PR spin
If you can't see the spin on corporate messaging it means it's working (and consequently, to stretch the metaphor, your wicket is in danger).
This article is just an ad / public-service-announcement for various paid Tailscale features, though?
And you're under the impression that the purpose of a company blog is WHAT, exactly?
I have recently noticed that the words "ad" or "marketing" have become, in and of themselves, with no additional information or context, slurs or dismissals.
I understand why. The modern internet has turned advertising into a morass of constant bombardment and the only sane response is to block as much as possible and ignore as much else as possible.
But it's unfortunate because, in some sense, ever single thing that a company every says that is not legally mandated in some way is a form of advertising.
And in many cases, that "advertising" contains true, useful information that can be helpful.
What is important isn't whether or not something is an "ad", but instead, whether or not it contains true information that is helpful in some way.
Many ads don't reach this bar. They are either misleading, straight up lying, or information that is almost completely useless.
But when I'm searching for a particular product, about the only source of information at all is some form of advertising, and I almost always find at least some amount of it to be helpful in making a product decision.
Ads are more often than not polluting to the informational ecosystem, but that's not because they are ads.
1 reply →
The person I'm replying to says they deserve "a lot of respect for this"
3 replies →