> Tailscale contracts with cybersecurity firm Latacora to conduct
And these published audits of the `tailscale` software are where ?
Even half-serious VPN providers like Mullvad publish in public their regular security audits of their app and infrastructure.
There is zero reason Tailscale cannot do the same.
And frankly, given the nature of this vulnerability, "insecure argument handling" I'm not entirely sure it has been audited ? Or if it has, they should be looking for a new auditor ASAP !
> I'd class Mullvad as the most serious VPN provider
I agree. Its annoying that lots of places have recently been blanket-banning Mullvad IP ranges.
Their sister-company Tilitis[1] is also doing interesting things with the Tkey product.
The present version has limitations due to the original security model but the up-and-coming version has a revised security model to make things a bit more "real-world" useful whilst not making any security trade-offs.
And these published audits of the `tailscale` software are where ?
Even half-serious VPN providers like Mullvad publish in public their regular security audits of their app and infrastructure.
There is zero reason Tailscale cannot do the same.
And frankly, given the nature of this vulnerability, "insecure argument handling" I'm not entirely sure it has been audited ? Or if it has, they should be looking for a new auditor ASAP !