Hacker News new | ask | show | jobs
by ahmedehab_01 1 day ago
This actually shows that it was a human error on HuggingFace's end that led to that "breach".

I would say HuggingFace needs to prioritize both security metrics/alerts and metrics/alerts for node count. And not leave long-lived keys accessible easily like this.

It would have been way more groundbreaking if the agent found an actual vulnerability in Tailscale.

2 comments

I think the situation is slightly more nuanced than that. When the easiest path by far is long lived keys, there is something to be said about the security posture of a solution where those are the default behavior, especially if they don’t actively discourage usage in documentation. For instance if you go to aws and try to create an iam user with access key/secret key they warn the shit out of you multiple times. They say things like “this is a bad idea” “we don’t recommend this” and “use this better solution instead”. I think if you’re providing an auth service like this you have some level of responsibility to guide people towards the less naive solution - part of what you’re selling in an auth offering is security, so if you default to garbage security, you don’t have a very good offering
Huggingface being a laboratory harbouring dangerous models in hibernation, should've been more careful from start