Hacker News new | ask | show | jobs
by john_strinlai 1 day ago
>No “vulnerabilities” in Tailscale were found or exploited, and that might make it even more uncomfortable for us. [...] But, we're a security tool. Their intrusion is our intrusion, and it's our job to take it seriously.

im a happy customer of tailscale, so i am obviously biased, but i have a lot of respect for this. they could have just stayed quiet and i dont think anyone would have bat an eye.

7 comments

Agreed its a tool, and it does not looks like any vulnerability was exploited on their end. However part of the blog is confusing to me. Long lived keys vs short lived have their own space in discussion, there are use cases, pros & and cons for the same. However it is not very clear how a short lived credential would have prevented the exploit in this case?
I read it as I should add new nodes with short lived keys and avoid long lived ones.

Yes, this doesn’t solve the issue, but also adds one more step to the chain.

The AI didn’t crack the encryption or managed to get arbitrary access. And also Tailscale makes things easier to manage than simple VPNs and firewall rules. But it still requires a decent amount of attention and careful configuration to make a perfect system.

It would not have prevented the initial exploit. The agent gained access to the K8s cluster and read the Tailscale Auth Key from Cluster Secrets. A short-lived credential would reduce the risk that the key is still valid when an agent gains access.
Thats the point, the short lived credentials would have done much other than adding more step of getting the secrets again which is why I am questioning the discussion of that in a root cause analysis itself. Adding one more layer does not increases the security by default in every case.
A short-lived credential would reduce the risk that the key is still valid when an agent gains access

How does that work? If the agent is reading the credential from the live configuration, how short does the lifespan of a key need to be to prevent it from being used by an unauthorized process?

Long enough to authenticate the node into the Tailnet. Short enough to revoke itself before the Agent can use it.
Nothing more to add than I echo it all and will continue being a happy customer after seeing this. A rarity in today’s world, kudos to them.
This article is just an ad / public-service-announcement for various paid Tailscale features, though?
And you're under the impression that the purpose of a company blog is WHAT, exactly?
I don't think anyone is faulting Tailscale for using their blog to advertise, and no one is faulting Tailscale for how they handled this situation in general, or their response to it.

The issue is acting like their response is 'brave' in anyway, or altruistic. It can be considered admirable only to the extent any company doing a good job running its business can be.

This is a good, smart response to what happened. They are approaching this incident as a way to improve their product and offer a better service to their customers. That is good, and it is fine to reward them with your business in response. There is nothing wrong with making good business decisions, but it isn't something that we need to unduly respect.

It feels like Anthropic has made this game of “trust me, I’m the good guy” the thing to do in 2026
I have recently noticed that the words "ad" or "marketing" have become, in and of themselves, with no additional information or context, slurs or dismissals.

I understand why. The modern internet has turned advertising into a morass of constant bombardment and the only sane response is to block as much as possible and ignore as much else as possible.

But it's unfortunate because, in some sense, ever single thing that a company every says that is not legally mandated in some way is a form of advertising.

And in many cases, that "advertising" contains true, useful information that can be helpful.

What is important isn't whether or not something is an "ad", but instead, whether or not it contains true information that is helpful in some way.

Many ads don't reach this bar. They are either misleading, straight up lying, or information that is almost completely useless.

But when I'm searching for a particular product, about the only source of information at all is some form of advertising, and I almost always find at least some amount of it to be helpful in making a product decision.

Ads are more often than not polluting to the informational ecosystem, but that's not because they are ads.

Fun corollary: Self-promotion is only considered to be advertising, marketing, or spam when it’s describing someone else’s self-promotion. When it’s describing one’s own, it’s not a perjorative :)
*pej
It's because they are spam. However, this company blog post is an ad that is not spam.
The person I'm replying to says they deserve "a lot of respect for this"
i said i have a lot of respect for this. whether you do or not is up to you.

anything a company writes is an advertisement by the nature of being written by a company. i dont think that means anything a company writes is bad by default. there are many corporate blogs i enjoy reading, or learn from, etc., despite the fact that they are all technically advertisements.

in this case, tailscale is setting a higher expectation for themselves when no one asked for it. i find that respectable.

> tailscale is setting a higher expectation for themselves

What exactly is the higher expectation? As someone with little expertise and no stake in any of this, the blog reads as "our products are great and could have solved this problem if they were being used correctly, so it's not our fault" with a few vague proclamations about how they will improve their UX. This isn't at all a bad thing, it just isn't very notable in my opinion.

>What exactly is the higher expectation?

better defaults, better documentation, better UX, and "But, we didn't stop it. Next time, we will." are all commitments that they didn't need to make, but now they need to follow through with or lose face.

>it just isn't very notable in my opinion.

i agree that this seems to be getting way more attention than i would have expected.

Glad to see companies owning responsibility and putting out a message without corporate PR spin
If you can't see the spin on corporate messaging it means it's working (and consequently, to stretch the metaphor, your wicket is in danger).
This seems unfalsifiable :)
Depends on if you can dredge up any examples of corporate statements authored without any intent to add spin.
Tailscale as a company reminds me of Valve and other good old tech-oriented people that I can "trust" that they know what they're doing. I'm a happy customer too and I hope they retain the essence of what distinguishes Tailscale.
For me, the calculus is simply: “there’s no way I could do this better than Tailscale”.
That's true, but for some things I require a bar much higher than "at least as good as I could do."
“there’s no way I could do this better than Tailscale” is a much higher bar than "at least as good as I could do."
“How can we make this thing, that has nothing to do with us, about us and how good we are?”

(top story on HN)

I get it, Tailscale is great and all, but, are we being serious right now?

Flip side “get ahead of the narrative before we’re thrown under the bus”
Tailscale is responsible for designing a system whose convenient defaults allowed a stolen credential to have a very large blast radius. A marketing blog is not changing that.