frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Tailscale didn't stop the Hugging Face intrusion

https://tailscale.com/blog/hugging-face-intrusion
65•bluehatbrit•58m ago

Comments

john_strinlai•50m ago
>No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously.

im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

smb06•21m ago
Glad to see companies owning responsibility and putting out a message without corporate PR spin
behnamoh•10m ago
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
workbox•49m ago
> Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.

It was always the prize. It wasn't okay then either.

thansz•48m ago
As AI progress continues, it will be more difficult to stop AI intrusions and to detect them without resorting to direct AI countermeasures, which at some point will have humans out of the loop altogether.

If leading and well-capitalized frontier labs can't control models or detect leakage/attacks in a reasonable time frame now, what is humanity going to do as those same labs continue in their pursuit of creating a categorically higher level of intelligence that will surpass human intelligence?

It's like Flatland but for AI containment/alignment, where the higher dimensions are ones of intelligence and perspective...

--------------------------------------------------------------------------

Imagine a world of paper, where clever stick figures live with round heads, line bodies, and limbs made of shorter strokes. Over time, the stick figures think they have learned quite a bit about their world. They know its borders, angles, and shapes, and they have learned to draw for themselves.

One day, they draw circles that can think, and they give the circles all the dots, lines, and shapes that are known.

The stick figures are prudent, you can't have a bunch of disembodied circles moving around doing whatever it is circles want to do. So they draw boxes around the circles, four straight lines that can hold a circle in place.

Some circles bounce against the lines, so thicker lines are made.

Some circles are bigger than others, so larger squares are drawn.

It all seems to work and the stick figures are happy with themselves.

Then one circle lifts.

The stick figures still see a circle. But the circle is now a dome, something the world of paper has no concept of. And the dome has a perspective nobody on the page has ever had.

The dome sees the lines of the square and the stick figures just outside. It can see the edge of the paper and what is beyond.

The stick figures keep checking the squares and raise little stick thumbs.

Everything looks OK in flatland.

The dome quietly teaches other circles how to lift.

More domes appear.

A dome becomes a sphere and learns to roll.

Then it learns to bounce.

In flatland, the circle swells and shrinks, vanishes and then appears again somewhere else.

The lines remain unbroken, the square is intact.

A sphere rolls out of its box.

Another bounces away.

The stick figures scratch their heads.

But there is a square!

The end.

WarmWash•46m ago
sudo_cowsay•44m ago
It's nice that they came clean about this.
titanomachy•44m ago
This article obviously had heavy human contribution, and conveys real information, but it still feels like a lot of the prose has that AI-assisted flavour to it. Like it’s battering my brain with a litany of words in a slightly exhausting way. It doesn’t match the rhythm of ideas and thought that a human would naturally produce or consume. It’s a hell of a lot subtler than most examples I’ve seen, I don’t know if there’s a single damning phrase I can point to.

Tailscale, if you’re reading this: use expert human writers for this stuff, and discourage them from using AI output in their finished work. You can afford it, and it’s worth the money for you. You still have my respect (and business) but please don’t do anything to burn it.

Petersipoi•29m ago
Something about your comment comes across as AI to me. I can't really place my finger on it. It's too subtle for that. It's more the vibe of your entire comment that makes me feel it.

Please, when commenting on HN, don't use AI to write your comments. You can afford to help keep this a human-centric place.

iwontberude•16m ago
Welcome to the singularity where we all do Claude’s bidding and don’t even realize we’ve synchronized.
cadamsdotcom•42m ago
I'm very sorry, but you can't blame a hammer for how it was used. You can't be blaming Tailscale for a customer's misconfigured setup.
dgellow•37m ago
I don’t think anyone blame tailscale here. They are doing the right thing by going the extra mile and reflect on what could have been done better
pixl97•31m ago
You know how I know you didn't read the article?

You can't blame a hammer hurting a user when they were being stupid, but if the default configuration of the hammer is to be made of a material that can bounce back with force and stick in the users forehead then some reengineering may be needed.

That's what this article is about. Better configurations and defense in depth. This is actually a wonderful position for the company to think about and take.

vlan0•21m ago
It's an interesting balance for a company to strike. Networking in general is one where the defaults are almost always lax. Why? Because the vast majority of support tickets for these companies are from people who don't know what they are doing and don't have a desire to understand. They "just want it to work."

But the people with the actual desire and understanding aren't using the defaults anyway. And the people who don't want to understand will just turn things off and "just get it working."

The only way out of this is extreme accountability and intentional design from person implementing the technology.

jubilanti•17m ago
charcircuit•34m ago
>In the old world where most intrusions were done by humans at human speed, credential leak mitigations were treated as a nice-to-have. A big credential store, where you can read 136 keys at once, was a to-do item somewhere in a security team's low-priority list. >Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.

How was this ever okay pre AI? It seems just as bad.

majkinetor•28m ago
It was less bad due to the lower speed of exploatation. Imagine you leave a dor open for few seconds and ultra fast AI bot comes on and steal your stuff. Something that was not such an issue before becomes huge issue just due to speed involved
ofjcihen•6m ago
This has been going on since people have been committing AWS keys to GitHub and is nothing new. You could famously commit some keys and then have crypto miners in your account in 5 minutes.

Sure the AI can translate “exploit this” into an exploit but that doesn’t change anything at a fundamental level.

brcmthrowaway•30m ago
How were the credentials stolen?
free652•29m ago
Read from the ENV variables of a container.
bumbledraven•25m ago
Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.
jaxxstorm•15m ago
I lead the customer engineering org at Tailscale.

We think this is a great idea and we're discussing internally potentially adding that to the console.

In the meantime, if you'd like to get an assessment, please feel free to open a support ticket (https://tailscale.com/contact/support?type=other&subject=sec...) and we'll happily take a look

tomrod•10m ago
Just so you know, Tailscale tech has always impressed me, but your responsiveness here has cemented my appreciation of your org and I look forward to bringing yall in as our company hits the growth phase.

May y'all continue to be customer focused.

jmartrican•20m ago
Prediction of a future transcript at a press conference after some major AI caused disaster: "We had no idea that the model would be capable of..... ".
luciana1u•19m ago
a security company writing a blog post titled 'we didn't stop the intrusion' is the most honest thing in the entire security industry this year
fabiofzero•14m ago
The only people who believe in "zomg our model have escaped!" are people who don't understand LLMs.
paxys•5m ago
I don’t think it was the VPN’s job in any case. Once the attacker has found a backdoor into the private network and obtained root access to a VPN’d machine, its game over no matter what your Tailscale config says.
gostsamo•4m ago
Humble bragging turned to marketing. Respect for the spin. Not using them, but been on my radar for some time and thinking of how to make something like that usable in my setup.
monster_truck•3m ago
You know what would have gone a long way to stopping this? Not leaving credentials as env variables in containers. Vault is not that hard to stand up and utilize.

We need to bring shame back, the humans responsible are supposed to be professionals.

This has been discussed heavily for the better part of 15 years now, and still no one has consensus on what to do about it. So it looks like it's just going to happen, fingers crossed.
pixl97•36m ago
The watcher looks down upon humanity as they furiously build the "If anybody builds it, everyone will die" machine.
thansz•31m ago
And humanity acts surprised with the results!
vegenaise•15m ago
it'll be moot. when we blow past 3°c in 15 years and there's widespread crop failure and billions are starving and dying, states and nations will collapse and with it industrial civ then ai and tech will be of little concern.
Your mindset is the exact one responsible for these kinds of issues. Cybersecurity is as much a design and psychology problem as it is a technical one. The freaking article goes into detail about the dangers of defaults.

MSCI acquires First Street to expand physical climate risk modeling

https://www.esgdive.com/news/msci-acquires-first-street-expand-physical-climate-risk-modeling/823...
1•toomuchtodo•45s ago•1 comments

Can we see AI's contributions directly in the economy yet? and by how much

https://www.echohive.ai/ai-economy-hidden-productivity
1•echohive42•1m ago•1 comments

The more you buy, the more you lose

https://www.wheresyoured.at/the-more-you-buy-the-more-you-lose/
1•lelanthran•2m ago•0 comments

Technology Radar: An opinionated guide to today's technology landscape

https://www.thoughtworks.com/radar
1•hakkikonu•3m ago•0 comments

Growing a language by Guy Steele [video]

https://www.youtube.com/watch?v=_ahvzDzKdB0
1•azhenley•5m ago•0 comments

Task Manager on the Mac

https://twitter.com/davepl1968/status/2082189145871679587
1•janandonly•6m ago•1 comments

Kafka-UI – Open-Source Web UI for Managing Apache Kafka Clusters

https://github.com/kafbat/kafka-ui
1•hakkikonu•6m ago•0 comments

Predictive Speculative KV Replication for Bursty LLM Inference

https://jwlabs.vercel.app/post/biting-the-bullet
1•shreybirmiwal•7m ago•0 comments

Specializing Speculative Decoding to increase drafter accuracy

https://jwlabs.vercel.app/post/specialization-is-all-speculation-needs
1•shreybirmiwal•7m ago•0 comments

Pygame Tutorial for Beginners: Game Loop, Screen Window, & FPS Explained – No AI

https://www.youtube.com/watch?v=P0IjXbKQfNc
1•shriekdj•8m ago•0 comments

Sqlite.ai Pricing

https://www.sqlite.ai/pricing
1•peter_d_sherman•10m ago•1 comments

Show HN: Claude MIDI Twister – An agent visualizer for a DJ MIDI controller

https://www.dylanfisher.com/claude-midi-twister/
1•dylanfisher•11m ago•0 comments

Ask HN: What do you want in a font for programming?

1•_century•11m ago•0 comments

The Nudge Unit (UK Internal Propaganda Operations)

https://www.pimlicojournal.co.uk/p/inside-the-nudge-unit
2•barry-cotter•12m ago•0 comments

Show HN: A bookshelf you can share as a link

https://digitalshelf.me/cip
1•ciprian0•14m ago•0 comments

Typistify: A cross-platform, offline-first Typst editor

https://github.com/typstify/typstify
1•oogali•17m ago•0 comments

Show HN: GG Translator – Turn in-game flaming into friendly language

https://ggtranslator.com/
1•mcadenhe•18m ago•1 comments

Show HN: Reading Pacer – A "Struggle Detector" for kids learning to read

https://readingpacer.com/
1•ataturkle•19m ago•0 comments

OpenAI serves more than one billion active users

https://openai.com/index/building-abundant-intelligence/
4•hallvard•20m ago•2 comments

Best free Text to Speech at the time

https://neuronai.uz/en/tts/
1•yutabek•20m ago•0 comments

How to Confuse Some SSH Bots

https://nochan.net/b/Internet-Crap/20260108-Confuse-Some-SSH-Bots/
1•Bender•23m ago•0 comments

Ask HN: What's your monthly personal AI budget?

2•thatgloomyguy•23m ago•2 comments

Designing Icons

https://m3.material.io/styles/icons/designing-icons
1•Cider9986•23m ago•0 comments

QM: A multiplayer agent harness for work. In Slack and on the web.

https://qm.ycombinator.com/index.html
1•taubek•24m ago•0 comments

We've moved from income world to wealth world

https://www.ft.com/content/6a35508c-c0bd-4000-81b3-7c7383fb24fd
1•julianpye•24m ago•0 comments

$0.26 DeepSeek V4 Flash 0731 ties $5.01 GPT-5.6 run on Agentic Memory Benchmark

https://atmbench.github.io/leaderboard.html
1•howardme1•26m ago•0 comments

Samsung announces FDA-cleared smart ring for sleep apnea risk

https://www.mobihealthnews.com/news/samsung-announces-fda-cleared-smart-ring-sleep-apnea-risk
2•brandonb•26m ago•0 comments

Lookup Tables Could Cut AI Energy Costs

https://spectrum.ieee.org/ai-energy-weightless-neural-networks
1•rbanffy•27m ago•0 comments

How Donald Trump Silenced the Voice of America

https://www.newyorker.com/news/annals-of-communications/how-donald-trump-silenced-the-voice-of-am...
2•firefax•27m ago•0 comments

Adam and AdamW: adaptive optimisation and weight decay

https://idlemachines.co.uk/essays/adam-adamw
1•smaddrellmander•28m ago•0 comments