logoalt Hacker News

Tailscale didn't stop the Hugging Face intrusion

142 pointsby bluehatbrittoday at 7:03 PM48 commentsview on HN

Comments

john_strinlaitoday at 7:12 PM

>No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously.

im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

show 4 replies
ahofmanntoday at 8:19 PM

Wow, this article is super smart marketing by tailscale. Not only do they list all the nice and expensive features, that can help in such a situation but they also show that someone at huggingface made a very stupid thing by writing a reusable auth key in an env file. Everyone using mesh VPNs like tailscale, netbird etc. knows that this is like leaving the keys right at the door.

simonwtoday at 8:27 PM

> One of those 136 credentials was a reusable Tailscale auth key, used to create new Tailscale CI (continuous integration, used for automated testing) nodes in their tailnet. The agent copied that key into a series of external sandboxes and used it, over several days, to enroll a total of 181 nodes into Hugging Face’s tailnet. Those nodes each received a Tailscale identity tag granting all the access a CI node would get.

This feels like an alerting opportunity. I wonder what the lowest friction way would be for Hugging Face to have alerts if 181 unexpected nodes were added to a tailnet.

iamspoilttoday at 8:02 PM

Quoting Tailscale: This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit Tailscale, and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will.

show 1 reply
paxystoday at 7:57 PM

I don’t think it was the VPN’s job in any case. Once the attacker has found a backdoor into the private network and obtained root access to a VPN’d machine, it’s game over no matter what your Tailscale config says.

bumbledraventoday at 7:37 PM

Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.

show 2 replies
jmartricantoday at 7:41 PM

Prediction of a future transcript at a press conference after some major AI caused disaster: "We had no idea that the model would be capable of..... ".

luciana1utoday at 7:43 PM

a security company writing a blog post titled 'we didn't stop the intrusion' is the most honest thing in the entire security industry this year

colek42today at 8:05 PM

I really wish they would support SPIFFE/SPIRE

sudo_cowsaytoday at 7:18 PM

It's nice that they came clean about this.

yieldcrvtoday at 8:05 PM

This is respectable

They aren’t hiding behind industry best practices or a solid liability punting contract

There saying the best practices should change, apologizing, and changing their own behavior

Take notes

gostsamotoday at 7:57 PM

Humble bragging turned to marketing. Respect for the spin. Not using them, but been on my radar for some time and thinking of how to make something like that usable in my setup.

show 1 reply
charcircuittoday at 7:28 PM

>In the old world where most intrusions were done by humans at human speed, credential leak mitigations were treated as a nice-to-have. A big credential store, where you can read 136 keys at once, was a to-do item somewhere in a security team's low-priority list. >Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.

How was this ever okay pre AI? It seems just as bad.

show 1 reply
cadamsdotcomtoday at 7:19 PM

I'm very sorry, but you can't blame a hammer for how it was used. You can't be blaming Tailscale for a customer's misconfigured setup.

show 4 replies
workboxtoday at 7:12 PM

> Now, in a world of rogue AI agents, the big credential vault is the prize. It's not okay anymore.

It was always the prize. It wasn't okay then either.

a-dubtoday at 8:10 PM

[dead]

titanomachytoday at 7:18 PM

[flagged]

show 1 reply
brcmthrowawaytoday at 7:32 PM

How were the credentials stolen?

show 1 reply
fabiofzerotoday at 7:48 PM

The only people who believe in "zomg our model have escaped!" are people who don't understand LLMs.

thansztoday at 7:13 PM

As AI progress continues, it will be more difficult to stop AI intrusions and to detect them without resorting to direct AI countermeasures, which at some point will have humans out of the loop altogether.

If leading and well-capitalized frontier labs can't control models or detect leakage/attacks in a reasonable time frame now, what is humanity going to do as those same labs continue in their pursuit of creating a categorically higher level of intelligence that will surpass human intelligence?

It's like Flatland but for AI containment/alignment, where the higher dimensions are ones of intelligence and perspective...

--------------------------------------------------------------------------

Imagine a world of paper, where clever stick figures live with round heads, line bodies, and limbs made of shorter strokes. Over time, the stick figures think they have learned quite a bit about their world. They know its borders, angles, and shapes, and they have learned to draw for themselves.

One day, they draw circles that can think, and they give the circles all the dots, lines, and shapes that are known.

The stick figures are prudent, you can't have a bunch of disembodied circles moving around doing whatever it is circles want to do. So they draw boxes around the circles, four straight lines that can hold a circle in place.

Some circles bounce against the lines, so thicker lines are made.

Some circles are bigger than others, so larger squares are drawn.

It all seems to work and the stick figures are happy with themselves.

Then one circle lifts.

The stick figures still see a circle. But the circle is now a dome, something the world of paper has no concept of. And the dome has a perspective nobody on the page has ever had.

The dome sees the lines of the square and the stick figures just outside. It can see the edge of the paper and what is beyond.

The stick figures keep checking the squares and raise little stick thumbs.

Everything looks OK in flatland.

The dome quietly teaches other circles how to lift.

More domes appear.

A dome becomes a sphere and learns to roll.

Then it learns to bounce.

In flatland, the circle swells and shrinks, vanishes and then appears again somewhere else.

The lines remain unbroken, the square is intact.

A sphere rolls out of its box.

Another bounces away.

The stick figures scratch their heads.

But there is a square!

The end.

show 2 replies
monster_trucktoday at 7:58 PM

You know what would have gone a long way to stopping this? Not leaving credentials as env variables in containers. Vault is not that hard to stand up and utilize.

We need to bring shame back, the humans responsible are supposed to be professionals.

show 1 reply