| ▲ | traceroute66 an hour ago | ||||||||||||||||||||||||||||||||||||||||
> I can "trust" that they know what they're doing I wish I could say the same. At $work we use Tailscale but only bare minimum and at arms length and only because we have to (people were having NAT issues with standard Wireguard). None of their code has had a security audit, let alone regular ones. Yes they make a big song and dance about SOC2/ISO27001 but that is NOT the same thing, that's just shiny tick-boxes for compliance departments. They seem to rely entirely on the random goodwill of others to do random audits of unknown coverage at random intervals, not exactly reassuring. "Tailsale Lock" is, being polite, a hot mess. So many sharp edges and footguns. Their introduction of TPM-by-default and then removing it a few weeks later because of a seemingly small number of edge-cases and very odd reasoning was just weird. Yes they are nice guys to chat to and all that. But for a security tool they need to up their game seriously. | |||||||||||||||||||||||||||||||||||||||||
| ▲ | apenwarr 24 minutes ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||
(Tailscale CEO) You have posted here multiple times that "none of the code has had a security audit" and that the SOC2 audit "is not the same thing." It's true that those two audits aren't the same thing. However, the SOC2 auditor confirms, in the published report, that Tailscale has regular and ongoing security audits including penetration tests and many kinds of code reviews. The security audit report, which you perhaps imagine to be a long list of vulnerabilities... doesn't look like that. It says we don't have a long list of vulnerabilities. The security bulletins are all here: https://tailscale.com/security-bulletins | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
| ▲ | aborsy an hour ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||
It does too many things, and the product has got too complex. I saw a year ago they were looking for someone just to help with complexity. I use it but feel uncomfortable, that it has large attack surface and LLMs will find exploits in it. Without taillock it makes no sense. Anyone on their coordination servers will be able to connect to your network. | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||