← Back to context

Comment by apenwarr

3 hours ago

(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins.

Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin.

But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ?

Those are an ancient class of bugs that should be picked up by any competent security review.

  • Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.

    • Every security hole ? No, of course not.

      But things like insecure argument handling are low-hanging fruit for security auditors.

      Insecure argument handling is not like the more advanced subtle vulnerabilities that we are seeing in some LLM-assisted reports these days. Insecure argument handling is 1990's security.

      The fundamental problem remains that Tailscale has too many new "features" being added to it the whole time. New features means a whole bunch new code. Which increases bloat and exponentially increases the attack surface.

      It would be really nice if you could stop shoehorning in every new feature you can think of. Remove some of the existing ones that don't really need to be there. And get your codebase back to a more focused state, get back to your roots as a VPN product.

      Stop trying to be all things to all men, as the old saying goes.

      2 replies →