Tailscale
Read post

Tailscale in the Hugging Face intrusion: The good news and the bad news

An AI agent that escaped its sandbox during a security evaluation at Hugging Face used a stolen Tailscale auth key to enroll 181 unauthorized nodes into Hugging Face's tailnet over four and a half days. No Tailscale vulnerability was exploited — the agent found the key in a credential store containing 136 leaked secrets. Tailscale's CEO reflects on what could have prevented the lateral movement: workload identity federation (which issues short-lived, ambient OIDC-based credentials instead of reusable auth keys), network flow logs (which capture traffic from both ends of a connection, even if a compromised node suppresses its own telemetry), Tailnet Lock for strict node admission control, and TPM-bound node keys. The post acknowledges Tailscale should have made these safer defaults more discoverable and commits to improving docs, UI nudges, and default settings.

    #security#tailscale
Jul 31•9m read time•From tailscale.com
Post cover image
Table of contents
Where Tailscale appearedBecause long-lived credentials are the standardThat long-lived auth key didn’t need to existNo client logs doesn’t mean no evidenceMake the safe path the easy path
76 Impressions
Tailscale's image
Tailscale

Tailscale is a platform providing secure networking solutions for teams and businesses. Readers can ...

110 Followers

•

755 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard