Hacker News new | ask | show | jobs
by xyzzy_plugh 13 days ago
Have you tried asking them for a copy of such a report? Or is your plan to just continue complaining until they make one public?

The finding in TFA was the result of a security audit.

2 comments

As an open source maintainer of a fairly large project, we get reports from Ada Logics and similar firms every once in a while and those are absolutely not the same as a proper security audit (which we've also had commissioned in the past). Reports are just a description of a particular issue, not the deeper analysis of the general structure of the codebase that you get from a good audit.
> The finding in TFA was the result of a security audit.

Don't you fucking dare.

Might I point you to the words "We would like to thank Anthropic and Ada Logics for reporting this issue.".

It was not commissioned by Tailscale. It was DONE BY OTHERS AND REPORTED TO TAILSCALE. Just like the fucking disclosure tells you.

Tailscale should not be relying on the random goodwill of others to do random audits of unknown coverage at random intervals.

That is not a serious approach to security.

They should be commissioning their own, paid out of their own pocket, at regular intervals, and publishing the results.