Comment on: Tailscale didn't stop the Hugging Face intrusion
The majority of your security bulletins are as the result of third-party reports to you.Which, by definition, means they are not done by you, which means you don't know when they will be done or how much of your code base they are looking at.I think you know full well what I mean by a security audit. If you don't, go look at, for example, the ones that Mullvad publish for their software https://mullvad.net/en/blog/tag/audits.Please do not try to portray SOC2 as being the same thing as a code audit.And IF you have regular code audits, then please publish suitably redacted reports in public on y
Comment on: Tailscale didn't stop the Hugging Face intrusion
(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing."It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews.The security audit report, which you perhaps imagine to be a long list of vulnerabilities... doesn't look like that. It says we don't have a long list of vulnerabilities. The security bulletins are all here: https://tails
Comment on: Tailscale didn't stop the Hugging Face intrusion
> tailscale is setting a higher expectation for themselvesWhat exactly is the higher expectation? As someone with little expertise and no stake in any of this, the blog reads as "our products are great and could have solved this problem if they were being used correctly, so it's not our fault" with a few vague proclamations about how they will improve their UX. This isn't at all a bad thing, it just isn't very notable in my opinion.
Comment on: Tailscale didn't stop the Hugging Face intrusion
>In the old world where most intrusions were done by humans at human speed, credential leak mitigations were treated as a nice-to-have. A big credential store, where you can read 136 keys at once, was a to-do item somewhere in a security team's low-priority list.
>Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.How was this ever okay pre AI? It seems just as bad.