3 ms·
Bug reporter here: fwiw I just want to credit Tailscale for how they handled the disclosure and remediation. Deploying a prod fix within 24 hours is pretty gre
by tsujamin 4y ago
Bug reporter here: fwiw I just want to credit Tailscale for how they handled the disclosure and remediation.
Deploying a prod fix within 24 hours is pretty great, they’ve been super cooperative and pleasant to deal with and (as far as I could ascertain) there was no apparent way to get the database IDs for nodes you didn’t have pre-knowledge of
- fierro 4y agocould you not brute force them?
- tsujamin 4y agoSeems like they were randomly distributed over 2^64 ish so not feasible
- vdfs 4y agoWas there any bug bounty?
- bibabaloo 4y agoSuper cool find! Interested to hear how/why you came across this in the first place.
- louislang 4y agoGreat find! Were you actively looking, or did you just stumble on something that set off your spidey-sense?
- tsujamin 4y agoJust the latter while I was managing something in my tailnet
- louislang 4y agoI'm always amazed how often that happens. Again, excellent finding.
- imdsm 4y agoI wonder how many bugs are found this way, rather than actually looking. I found a way to extract private emails from npm a while ago, purely through chance.
- louislang 4y agoIf I had to guess, quite a few. I've reported my fair share of security issues and a number of them started out by accident.
- insomniacity 4y agoDo we know that this would be mitigated by https://tailscale.com/blog/tailnet-lock/ https://tailscale.com/blog/tailnet-lock/? My instinct is yes...
- tailscaletom 4y agoYes. Peers added in this fashion would not have been signed by a trusted tailnet-lock key, so clients would refuse to trust them.
- nunez 4y agoyup, the tailscale team is awesome